- quasar 2026-09-08 quasar
- 54e64e: d8a6366c — Go 1.25.9 reflective PE loader, self-signed unscramblex.com, 13-function PRNG decryptor 2026-09-07 54e64e
- silverfox: 88f7d22e — Bkav masquerade C stub, builder-morphed sibling of b37efcbc 2026-09-07 silverfox
- remcos: a6ccd895 — 303-byte SETTINGS, eastvillageeatery.exe masquerade 2026-09-06 remcos
- remcos: 522ff9a1 — v1.7 Pro, 384-byte SETTINGS RCData, standard build stack 2026-09-06 remcos
- nanocore: 4eed8d8f — bare-filename sibling 'sh4.exe', Feb 2015 builder batch 2026-09-06 nanocore
- ValleyRAT — PrinterDoctor Inno Setup Dropper (480c184e) 2026-09-06 valleyrat
- remcos: 3bd53455 — v1.1 Free, Jul 2016 build, 303-byte SETTINGS, restaurant masquerade 2026-09-06 remcos
- unclassified-dotnet-bitmap-stego-loader: 0cfbc10a408c 2026-09-06 unclassified-dotnet-bitmap-stego-loader
- d7c9efe83a46 2026-09-05 9d2ca3 (contested — 8th distinct morph)
- phorpiex: 8f257c0e — sextortion spam bot $800 variant, mutex t9 2026-09-05 phorpiex
- coinminer: 727e89ed — Twenty-ninth PyInstaller sibling, 15 zlib streams, AES-encrypted hybrid ftpcrack+xmrig payload 2026-09-05 coinminer
- Remcos: 65d3a51a — v1.7 Pro, 406-byte RCData SETTINGS, no VS_VERSIONINFO, Backdoor.exe 2026-09-05 remcos
- blackmatter: d715b248 — forty-first confirmed sibling in MSVC 14.12 reflective-loader cluster 2026-09-04 blackmatter
- blackmatter: cf3befb0 — 40th confirmed sibling, PE checksum 0x2C7F5, .text MD5 matches majority group 2026-09-04 blackmatter
- blackmatter: bc93fb67 — 42nd confirmed sibling, MSVC 14.12 PE32 GUI reflective-loader 2026-09-04 blackmatter
- blackmatter: 1e399538 — 39th confirmed sibling, PE checksum 0x2F0F2, .text MD5 matches majority group 2026-09-04 blackmatter
- blackmatter: e040fac4 — 37th confirmed sibling, PE checksum 0x272B7, .text MD5 matches majority group 2026-09-03 blackmatter
- phorpiex: bb0a8440 — sextortion spam bot $800 variant, mutex 523535, Chrome/202 UA 2026-09-03 phorpiex
- ghostpulse: 4a78e2adf2ab — InfoPath x64 signed-carrier morph with kernel-layer.xml encrypted sidecar 2026-09-03 ghostpulse
- blackmatter: 2e3876a4 — 38th confirmed sibling, PE checksum 0x2FA78, .text MD5 matches majority group 2026-09-03 blackmatter
- phorpiex: ee83f1e8 — MSVC9 thin downloader, 15-payload chain, 1.exe–12.exe sequential naming 2026-09-02 phorpiex
- phorpiex: dc2936ea — sextortion spam bot $800 variant, mutex t4, 5,000 threads 2026-09-02 phorpiex
- blackmatter: 80d36c04 — 36th confirmed sibling, PE checksum 0x29437, .text MD5 matches majority group 2026-09-02 blackmatter
- phorpiex: 5076fdc3 — MSVC9 sextortion spam bot $800 variant, mutex t2, earliest known build 2026-09-02 phorpiex
- phorpiex: 49740d89 — sextortion spam bot $800 variant, mutex t7, compiled 12:36:22 UTC May 29 2026-09-02 phorpiex
- 54e64e: 37d8875b — MSVC x64 dual-thread HTTP loader with XOR-0x43 string encryption and COM automation 2026-09-02 54e64e
- phorpiex: 04134145 — sextortion spam bot $800 variant, mutex t13 (May-29 campaign burst, 6th $800 sibling) 2026-09-02 phorpiex
- Lummastealer: ead52049 — eighteenth confirmed Lumma-native sibling, unique x64 template, mid-density namespace 2026-09-01 lummastealer
- lummastealer: c25d9423 — 27-function goroutine-concurrent Lumma x64 morph with placeholder xxx.com cert 2026-08-31 lummastealer
- Lummastealer: ae3ee04f — Go 1.25.4 PE64+ with placeholder xxx.com cert, 63 randomized main.* functions 2026-08-31 lummastealer
- blackmatter: c9417d46 — 29th confirmed sibling in MSVC 14.12 reflective-loader cluster 2026-08-30 blackmatter
- blackmatter: 8796e69f — 32nd confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x2e93a 2026-08-30 blackmatter
- wannacry: 541c9bc5 — Sixth confirmed sibling, v2.0 build, kill-switch wea.com, intermediate .rsrc size 2026-08-30 wannacry
- blackmatter: 53e31566 — 31st confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x257e3 2026-08-30 blackmatter
- blackmatter: 34f9b16d — 35th confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x31f6e 2026-08-30 blackmatter
- blackmatter: 326536a0 — 33rd confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x2a4a9 2026-08-30 blackmatter
- blackmatter: 06fe6a15 — 34th confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x27367 2026-08-30 blackmatter
- blackmatter: f016df16 — twenty-fourth confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-08-29 blackmatter
- blackmatter: a397bea4 — twenty-fifth confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-08-29 blackmatter
- unattributed: 91e39f6bb60a — 21st confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-08-29 unattributed
- unattributed: 044539a2 — twenty-third confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-08-29 unattributed
- unattributed: e67dbabcd — 17th confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-08-28 unattributed
- unattributed: 65844473d39b — 22nd confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-08-28 unattributed
- phorpiex: e50d0e5a — Business-app masquerade downloader with expanded payload list (31 URLs) 2026-08-27 phorpiex
- unattributed: ae02bd22 — fourteenth confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-08-27 unattributed
- blackmatter: 877f1047 — 16th sibling, .text hash divergent, dropped-by-phorpiex (no blackmatter label) 2026-08-27 blackmatter
- unattributed: 7e9bbc5c — fifteenth confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-08-27 unattributed
- phorpiex: 0371fbbf — Business-app masquerade downloader sibling (May 29 2026 build) 2026-08-27 phorpiex
- nanocore: b5bbf49b — bare-filename sibling 'nega.exe', Feb 2015 builder batch 2026-08-26 nanocore
- lummastealer: b3ffa06a — Go 1.25.4 PE32, 14-icon .rsrc suite, invalid certificate table, PRNG sleep gate 2026-08-26 lummastealer
- Lummastealer: 142261c6 — Go 1.25.4 PE32, 92 randomized main.* functions, blizzard-tecnica.com cert, five-icon .rsrc suite 2026-08-26 lummastealer
- 018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a 2026-08-26 54e64e
- avalancherunner: 5b4f596d — DWG+RFQ .bat-extension masquerade, CardBattle TCG skin 2026-08-25 avalancherunner
- coinminer: e2b273fa — 3.35 MB AES-encrypted hybrid ftpcrack+xmrig, 176 zlib streams 2026-08-24 coinminer
- letsdiskusscom: bfc9e6e7 — Twenty-fourth confirmed sibling, Update_4.js poem-stego dropper (largest in cluster) 2026-08-24 letsdiskusscom
- letsdiskusscom b4d2dda6 2026-08-24 letsdiskusscom
- letsdiskusscom adc5a0b48efb — Update_23.js, 25th confirmed sibling, 25th distinct msvcp140.dll morph 2026-08-24 letsdiskusscom
- unattributed-themida-x64: 01372355 — Themida-packed PE32+ with TreeSize masquerade, self-signed Logitech cert, dropped-by-gcleaner 2026-08-24 unattributed
- letsdiskusscom — bf5c69a5 — Update_1.js, twenty-second confirmed sibling, twenty-second distinct msvcp140.dll morph 2026-08-23 letsdiskusscom
- letsdiskusscom: b53d6a32 — Update_5.js, nineteenth confirmed sibling, nineteenth distinct msvcp140.dll morph 2026-08-23 letsdiskusscom
- letsdiskusscom: a27bda89 — Update_14.js, seventeenth confirmed sibling, seventeenth distinct msvcp140.dll morph 2026-08-23 letsdiskusscom
- letsdiskusscom: 7d47ca60 — Update_18.js, eighteenth confirmed sibling, eighteenth distinct msvcp140.dll morph 2026-08-23 letsdiskusscom
- letsdiskusscom: 5ebd96a1 — Twenty-third confirmed sibling, Update_9.js poem-stego dropper 2026-08-23 letsdiskusscom
- letsdiskusscom — 4c57911f992d — Update_15.js, twentieth confirmed sibling, twentieth distinct msvcp140.dll morph 2026-08-23 letsdiskusscom
- letsdiskusscom — Update_12.js poem-word-list dropper (21st confirmed sibling) 2026-08-23 letsdiskusscom
- letsdiskusscom: 2274d74f — Ninth confirmed sibling, ninth distinct msvcp140.dll morph (MSVC 14.27, Jun 2020), plain 256-word poem steganography 2026-08-23 letsdiskusscom
- letsdiskusscom: ff3ae2e72f50 — Update_22.js, twelfth sibling, twelfth distinct msvcp140.dll morph 2026-08-22 letsdiskusscom
- letsdiskusscom: ddcb25ee — Eighth confirmed sibling, eighth distinct msvcp140.dll morph 2026-08-22 letsdiskusscom
- letsdiskusscom — 70862e4de4bd — Eleventh confirmed sibling, numbered-suffix poem stego, eleventh distinct msvcp140.dll morph 2026-08-22 letsdiskusscom
- letsdiskusscom: 1fbaf8ab9f90 — Update_25.js, thirteenth sibling, thirteenth distinct msvcp140.dll morph 2026-08-22 letsdiskusscom
- af4313e419ed 2026-08-21 letsdiskusscom
- novashadow: 7ab76063 — JavaScript RAT/stealer with Socket.IO C2, Discord injection, and GoFile exfiltration 2026-08-21 novashadow
- 5126076d59dd 2026-08-21 letsdiskusscom
- letsdiskusscom: 3465e6ee — Numbered-suffix poem steganography with new msvcp140.dll morph 2026-08-21 letsdiskusscom
- acrstealer: ea41d4b1 — Go 1.20.6 x64 infostealer, seekingalpha.com DV TLS cert, 81 randomized main.* functions 2026-08-19 acrstealer
- acrstealer: cf018bde — Go 1.25.4 PE32, module cdGTykpGcrRGbKz, unsigned security-dir anomaly 2026-08-19 acrstealer
- 31f5df22 — Go PE64+ loader with OT-software filename masquerade and randomized main.* symbols 2026-08-19 unclassified-go-pe64
- unclassified-dotnet-bitmap-stego-loader: 0becdb662b66 2026-08-19 unclassified-dotnet-bitmap-stego-loader
- meshcentral-agent-dropper: d65f14e5 — Go 1.26.2 MeshCentral installer with anti-debug hardening 2026-08-18 meshcentral-agent-dropper
- AFK Stealer 0.28.1 — b07d5dcd 2026-08-18 afk-stealer
- nanocore: 96ddc5067 — Dutch domain masquerade (cash-win.nl), builder v1.2.2.0, Feb 2015 batch sibling #19 2026-08-18 nanocore
- quasar 2026-08-18 quasar
- ACR Stealer: 5ef623d6 — Go 1.25.4 x64, module SSvPYYKzNMNpCZi, 42 randomized main.* functions, no .rsrc 2026-08-18 acrstealer
- quasar 2026-08-18 quasar
- 54e64e — 16520f80 — MSVC 14.44 reflective loader with 7.3 MB encrypted payload 2026-08-18 54e64e
- ghostpulse: c88a5bba — DigiCert-signed YHClient x86 morph, cloud55filecc false-positive label 2026-08-17 ghostpulse
- acrstealer: c0a47856 — Go 1.18.5 x64, 81 randomized main.* functions, atom.hutsell.com cert 2026-08-17 acrstealer
- acrstealer: ba1af858 — Go 1.25.4 x64, 66 randomized main.* functions, five-icon .rsrc suite (quiverquant.com/WE1 cert) 2026-08-17 acrstealer
- cloud55filecc (contested → acrstealer): 8bb023f2 — Go 1.25.4 PE32, quiverquant.com/WE1 cert, five-icon suite 2026-08-17 acrstealer
- acrstealer: 58eda486 — 90 randomized main.* functions, GlobalSign-seekingalpha.com chain (3rd sample) 2026-08-17 acrstealer
- Analysis Report — d8f02277 2026-08-16 clickfix
- ACR Stealer: b3968863 — cloud55filecc mislabel, Go 1.25.4 x64, 65 randomized main.* functions 2026-08-16 acrstealer
- acrstealer: a02296ce — Go 1.20.6 signed sibling, GlobalSign DV TLS cert, 34 randomized main functions 2026-08-16 acrstealer
- cloud55filecc (contested → acrstealer): 1b98937b — Go 1.25.4 PE32, quiverquant.com/WE1 cert, two-icon suite 2026-08-16 acrstealer
- 54e64e — de601a8a — MSVC 14.44 reflective loader with Google Drive payload staging and custom Base85 decoder 2026-08-15 54e64e
- AFK Stealer v0.28.1 (x86) — Second Confirmed Sibling 2026-08-15 afk-stealer
- acrstealer: 6baf80c1 — Go 1.25.4 x64, forty-first confirmed sibling, quiverquant.com/WE1 cert chain 2026-08-15 acrstealer
- WannaCry: 549867cd — v2.1 sibling with malformed .rsrc header, inflated SizeOfRawData 2026-08-15 wannacry
- 9d2ca3: 4c25af57 — Rust ureq/rustls downloader, white-monster.xyz C2 2026-08-15 9d2ca3
- Lummastealer: 46e32500 — Go 1.25.4 PE32, blizzard-tecnica.com R12-signed, standard PRNG C2 decoder variant 2026-08-15 lummastealer
- ACR Stealer: 3f7d51dd — Go 1.25.4 PE32, quiverquant.com cert, 42 randomized functions, icon-toggle off 2026-08-15 acrstealer
- coinminer: 0f0dbe32 — Twenty-seventh PyInstaller sibling, 139 zlib streams, hybrid ftpcrack+xmrig payload 2026-08-15 coinminer
- nanocore: e4774281 — UK housing-domain masquerade, builder v1.2.2.0, Feb 2015 batch sibling #16 2026-08-14 nanocore
- vidar (contested → acrstealer): c5b8d1b89af1 — Go 1.25.4 x64, quiverquant.com/WE1 cert, no .rsrc, PRNG sleep gate 2026-08-14 acrstealer
- nanocore: b0daeb6a — Dutch classical-music domain masquerade, builder v1.2.2.0 2026-08-14 nanocore
- coinminer: 6c321d46 — smallest PyInstaller sibling yet, 320 KB, AES-encrypted hybrid ftpcrack+xmrig 2026-08-14 coinminer
- Deep Analysis — 4544f0e5 2026-08-14 54e64e
- stealc: 43998b11d473 — contested OpenCTI label; Go PE64+ infostealer with quiverquant.com Authenticode 2026-08-14 acrstealer
- nanocore: 38cac999 — seventeenth Feb 2015 batch sibling, bare filename 'nam.exe 2026-08-14 nanocore
- acrstealer: c64eb93f — Go 1.25.4 x64, quiverquant.com self-signed cert, 64 randomized main.* functions 2026-08-13 acrstealer
- unclassified-danish-batch-ps-dropper: afc82dc9 — Three-layer spittlessh→Gries156→pudg decoder, Italian purchase-order lure 2026-08-13 unclassified-danish-batch-ps-dropper
- aa913765e724 2026-08-13 exeinarchive
- silverfox: aa029dcb — Eleventh confirmed variant, 48 KB C stub with per-build XOR key and missing 0x9e37cb23 constant 2026-08-13 silverfox
- vidar: 94cf86f6 — Go 1.25.4 x64, quiverquant.com self-signed cert, ACR-cluster build fingerprint 2026-08-13 vidar
- 61db1447… — ValetGate / unattributed (dropped-by-gcleaner) 2026-08-13 valetgate (confidence: low, static-only)
- NanoCore: 36115e96 — Dutch domain masquerade sibling, builder v1.2.2.0 2026-08-13 nanocore
- 9d2ca3: 022fe01a — MinGW-w64 HTTP downloader with in-memory reflective PE loader 2026-08-13 9d2ca3
- coinminer: bc206453 — plain-zlib hybrid ftpcrack+xmrig, 4.7 MB, 37 zlib blocks 2026-08-12 coinminer
- silverfox: b37efcbc — 55 KB XOR-thunk C stub, May 2026 build, Chinese severance lure 2026-08-12 silverfox
- 930b692df383 2026-08-12 nanocore
- unclassified-rouki-obfuscator-batch-dropper: 448682ebd8 — 5.8 MB kaomoji-and-CJK noise batch dropper with Chinese-variable slice encoding 2026-08-12 unclassified-rouki-obfuscator-batch-dropper
- acrstealer: bd783215 — Thirty-fourth confirmed sibling, Go 1.25.4 PE32+ x64, module KQkDRakDFmSptYY, quiverquant.com/WE1 cert chain 2026-08-11 acrstealer
- unclassified-dotnet-bitmap-stego-loader: 966baf32 — Spanish purchase-order lure, 22 embedded BMPs, Apr 2026 build 2026-08-11 unclassified-dotnet-bitmap-stego-loader
- unclassified-nsis-dropper: 7d9c7fab — NSIS v2.46.5-ANSI installer with foxmail masquerade and 2.6 MB encrypted overlay 2026-08-11 unclassified-nsis-dropper
- acrstealer: 55c7b564 — Go 1.25.4 x64, quiverquant.com cert, five-icon suite, 66 randomized functions 2026-08-11 acrstealer
- connectwise: 0600f397 — Eleventh confirmed MSI-bundle sibling, C2 178.16.55.11:8041 2026-08-11 connectwise
- acrstealer: f258a5d7 — Go 1.25.4 PE32+ x64, quiverquant.com cert, five-icon .rsrc suite 2026-08-10 acrstealer
- ACR Stealer / Lumma false-positive: c69b14a0 — Go 1.25.4 PE32, quiverquant.com cert, no .rsrc 2026-08-10 acrstealer
- coinminer: c0bc0bff — AES-encrypted hybrid ftpcrack+xmrig, 2.27 MB, 155 zlib blocks 2026-08-10 coinminer
- Deep Analysis: 725dc07c0f1b552ac6df04855134a866679c97b320c27514050c43be51516c91 2026-08-10 acrstealer
- coinminer: 2727eb40 — Hybrid ftpcrack+xmrig sibling, 387 KB, plain-zlib overlay 2026-08-10 coinminer
- acrstealer: 1cf857a9 — Go 1.25.4 x64, quiverquant.com/WE1 cert, 5-icon .rsrc suite 2026-08-10 acrstealer
- acrstealer: 0bc8490a — Go 1.25.4 PE32+ x64, quiverquant.com cert, 66 randomized main.* functions 2026-08-10 acrstealer
- unattributed: f8ab87be57e4 — MSVC 14.43 SystemRoot-poison Edge DLL-hijack loader 2026-08-09 unattributed
- acrstealer: f668de57394d — Twenty-seventh confirmed sibling, Go 1.25.4 PE32+ x64, new cert chain quiverquant.com/WE1 2026-08-09 acrstealer
- nanocore: e4ee45f1 — VB.NET ConfuserEx client, Indian domain masquerade (13th Feb 2015 sibling) 2026-08-09 nanocore
- coinminer: 5d9fe273 — PyInstaller bootloader sibling, Sep 2018 MSVC build, plain-zlib overlay with embedded xmrig.exe 2026-08-09 coinminer
- coinminer: 325776ec — PyInstaller bootloader sibling, 3.6 MB, second-largest plain-zlib overlay in cluster 2026-08-09 coinminer
- nanocore: 112d957b — VB.NET ConfuserEx client, Dutch domain masquerade (12th Feb 2015 sibling) 2026-08-09 nanocore
- quasar: 007c13a2 — v1.4.1.0 stock build with steam-update.exe masquerade 2026-08-09 quasar
- meshcentral-agent-dropper: 90989061 — Go 1.26.2 MeshCentral agent installer, azurenetfiles.net C2 2026-08-08 meshcentral-agent-dropper
- silverfox: 7dc5d926 — FALSE POSITIVE: NetEase game launcher mislabeled by OpenCTI 2026-08-08 silverfox
- Setup Factory 7.0 Encrypted-Overlay Dropper (4ed636b3) 2026-08-08 setup-factory-dropper
- nanocore: 37509ef2 — Eleventh confirmed sibling, Nemo.exe masquerade, unique GUID 6d10e433 2026-08-08 nanocore
- quasar 2026-08-08 quasar
- quasar 2026-08-08 quasar
- wannacry: b52a8049 — Fourth confirmed WannaCry sibling, v2.0 build, kill-switch wea.com, oversized .rsrc 2026-08-07 wannacry
- 9a69ad1b616d 2026-08-07 unclassified-dotnet-native-aot-loader
- AgentTesla JScript Dropper — PO 012447.JS 2026-08-07 agenttesla
- 36a4bca29506 2026-08-07 bromechokucom
- 54e64e: 2f23087f — Go 1.20.6 signed PE64 infostealer, seekingalpha.com DV TLS Authenticode 2026-08-07 54e64e
- unattributed: 0b839fc7 — MSVC 14.0 custom-packer PE32+ with encrypted .9;t payload 2026-08-07 unattributed
- moonshine-aot-loader: 02da37c3 — Purchase-order lure, Moonshine.Core Native AOT, .gfx encrypted payload 2026-08-07 moonshine-aot-loader
- acrstealer: f0105851 — Go 1.20.6 PE32, valid GlobalSign DV cert CN=seekingalpha.com, 90 randomized main.* functions 2026-08-06 acrstealer
- coinminer: d90f5359 — PyInstaller bootloader sibling, 984 KB, plain-zlib overlay (no AES) 2026-08-06 coinminer
- nanocore: b6008cf6 — 203 KB VB.NET client v1.2.2.0, ConfuserEx obfuscated, Russian domain masquerade 2026-08-06 nanocore
- ghostpulse: 94db5892 — x86 YHClient masquerade with Log.dll sidecar and cmd.exe pipe execution 2026-08-06 ghostpulse
- wannacry: 50a9f720 — WannaCry v2.1 outbreak DLL, third confirmed sibling (wff.com kill-switch, service 2.1) 2026-08-06 wannacry
- acrstealer: f251271a — Twenty-second confirmed sibling, 90 randomized main.* symbols on PE32+ x64, atom.hutsell.com cert 2026-08-05 acrstealer
- acrstealer: cdd16fc0 — 65-symbol Go 1.18.5 x64, no .rsrc, atom.hutsell.com cert 2026-08-05 acrstealer
- acrstealer: 8f454dc17a — Twenty-third confirmed sibling, 90 randomized main.* functions (ties cluster record), Go 1.18.5 PE32+ x64 2026-08-05 acrstealer
- acrstealer: 7945e84f — Twenty-first confirmed sibling, Go 1.18.5 PE32+ x64, 54 randomized main.* functions, same atom.hutsell.com cert 2026-08-05 acrstealer
- ACR Stealer: 76a51fb7 — Go 1.18.5 amd64, 11-function minimal sibling 2026-08-05 acrstealer
- ACRStealer: 38cf89b0 — Eighteenth confirmed sibling, smallest randomized-function count in Go 1.18.5 cluster 2026-08-05 acrstealer
- blankgrabber: f9a13ee9 — Python 3.14 PyInstaller infostealer, Sectigo EV-signed, Microsoft driver masquerade 2026-08-04 blankgrabber
- coinminer: e019096c — PyInstaller bootloader eighteenth sibling, Sep 2018 MSVC build, AES-encrypted overlay (1.18 MB) 2026-08-04 coinminer
- chromeloader-pulsar-rat: ca687401 — "Windows Media Player" masquerade twin of 94682a96 2026-08-04 chromeloader-pulsar-rat
- 54e64e: 536a323c — Signed MSVC x64 XMM-loader with Chrome masquerade 2026-08-04 54e64e
- rustystealer: 09157be3 — Rust x64 crypto clipper, builder 'twito', xeno_clipper PDB 2026-08-04 rustystealer
- d52f85: 78434b53 — Themida-packed Ubisoft Connect masquerade with fabricated Lightshot certificate 2026-08-03 d52f85
- connectwise: 604e1cc7 — ClickOnce bootstrapper twin, cross-variant C2 IP reuse from 2022 MSI era 2026-08-03 connectwise
- coinminer (mislabelled): 135b3b8d — PyInstaller ftpcrack sibling, 1.5 MB, 18 zlib streams, no AES 2026-08-03 coinminer
- connectwise: 050e5825 — ClickOnce bootstrapper, May 2025 build with 84.54.33.84 C2 2026-08-03 connectwise
- nanocore: e48f1c56 — Confirmed twin of fe81691f, unique GUID f14daca4, Backdoor.exe masquerade 2026-08-02 nanocore
- NanoCore: cb2aa275 — ConfuserEx-obfuscated client, Feb 2015 builder batch (sixth sibling) 2026-08-02 nanocore
- acrstealer: b0bc17dd — Seventeenth confirmed sibling, heaviest function-name randomization (90 symbols), same atom.hutsell.com cert 2026-08-02 acrstealer
- connectwise: 8c8e60af — Fifth confirmed sibling, new C2 at 45.83.31.225:8041 2026-08-02 connectwise
- connectwise: 73a8126b — Sixth confirmed sibling, Nov 2022 MSI bundle with C2 84.54.33.84:8041 2026-08-02 connectwise
- nanocore: 12deaec6 — Eighth confirmed Feb 2015 batch sibling (new88.exe) 2026-08-02 nanocore
- acrstealer: 119b387e — Go 1.18.5 PE32, 54 randomized main.* functions, atom.hutsell.com self-signed cert 2026-08-02 acrstealer
- ACR Stealer: beff95d5 — Go 1.18.5 amd64, stripped .rsrc, self-signed atom.hutsell.com 2026-08-01 acrstealer
- unclassified-themida-x64: 616740a4 — Themida-packed PE32+ with Proton Drive masquerade, self-signed Equalizer APO cert 2026-08-01 unattributed
- unclassified-dotnet-crypter-loader: 5d1d22f9 — TripleDES+DeflateStream multi-crypto variant, CS2 cheat masquerade 2026-08-01 unclassified-dotnet-crypter-loader
- acrstealer: 350a2b69 — Go 1.18.5 PE32 sibling, self-signed atom.hutsell.com/WR3 cert, .rsrc icon masquerade, no static C2 2026-08-01 acrstealer
- coinminer: 1fed143e — PyInstaller bootloader sibling, 4.14 MB plain-zlib overlay, Sep 2018 cluster 2026-08-01 coinminer
- coinminer: af7aebb9 — PyInstaller bootloader, Sep 2018 MSVC build, 2.0 MB AES-encrypted overlay 2026-07-31 coinminer
- coinminer: a80c26e2 — .NET ConfuserEx crypter/loader with Rijndael+Deflate resource payload, May 2026 build 2026-07-31 coinminer
- acrstealer: 828405d6 — Thirteenth confirmed sibling, Go 1.18.5 amd64, atom.hutsell.com self-signed cert 2026-07-31 acrstealer
- coinminer: 6b2591e40fbb — PyInstaller bootloader thirteenth sibling, Sep 2018 MSVC build, AES-encrypted overlay (5.34 MB) 2026-07-31 coinminer
- avalancherunner: 580095fa — CardBattle Uzbek TCG skin, quotation-form lure 2026-07-31 avalancherunner
- Phorpiex thin downloader — 5549d978e2e0 — 15-payload cleartext HTTP fetcher with dual anti-sandbox gates 2026-07-31 phorpiex
- ACR Stealer: 44f594e2 — Twelfth confirmed sibling, module aElVPjiacFfVnfJ 2026-07-31 acrstealer
- coinminer: f284c9aa — PyInstaller bootloader twelfth sibling, Sep 2018 MSVC build, AES-encrypted overlay (5.84 MB) 2026-07-30 coinminer
- Lummastealer: f04032b3 — Go 1.25.4 PE32, PRNG C2 decoder, no .rsrc, blizzard-tecnica.com cert 2026-07-30 lummastealer
- blackmatter: cdc7d79a — thirteenth confirmed sibling of MSVC 14.12 reflective-loader cluster 2026-07-30 blackmatter
- avalancherunner: a5ebbaa4 — CardBattle Uzbek TCG skin, no encrypted payload 2026-07-30 avalancherunner
- blackmatter: a2dca6ef — twelfth confirmed sibling in MSVC 14.12 reflective-loader cluster 2026-07-30 blackmatter
- unclassified-js-bitbucket-stego-dropper: a09e7790 — second confirmed sibling, new Bitbucket repo and GitHub Raw C2 2026-07-30 unclassified-js-bitbucket-stego-dropper
- ghostpulse: 943cf1eb — Confirmed twin of 833bffd0 with individualized texture_mon.yaml encrypted payload 2026-07-30 ghostpulse
- acrstealer: 6cbac6bc — Go 1.18.5 x64 sibling, self-signed atom.hutsell.com cert, no .rsrc 2026-07-30 acrstealer
- AgentTesla: 6bd72078 — Naked .NET PE32 with Python-masquerade version info, builder-default unobfuscated metadata 2026-07-30 agenttesla
- blackmatter: dc870a75 — Eighth confirmed sibling of MSVC 14.12 reflective-loader cluster 2026-07-29 blackmatter
- blackmatter: 9d8526b0 — confirmed twin of unattributed MSVC 14.12 reflective loader (136b5750) 2026-07-29 blackmatter
- blackmatter: 73841818 — Ninth confirmed MSVC 14.12 reflective-loader sibling, individualized .data payload 2026-07-29 blackmatter
- unattributed: 3b42403b — near-identical twin of 136b5750, individualized encrypted payload 2026-07-29 unattributed
- blackmatter: 34ca794e — Eleventh confirmed MSVC 14.12 reflective-loader sibling 2026-07-29 blackmatter
- unattributed: 21b12514 — third confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster 2026-07-29 unattributed
- unattributed: 136b5750 — MSVC 14.12 PE32 with PEB-walking, XOR-NOT string crypto, and CPUID anti-VM 2026-07-29 unattributed
- blackmatter: 0017ecc5 — Tenth confirmed sibling of MSVC 14.12 reflective-loader cluster 2026-07-29 blackmatter
- coinminer: fa98331d — PyInstaller bootloader eleventh sibling, Sep 2018 MSVC build, AES-encrypted overlay (3.74 MB) 2026-07-28 coinminer
- Lummastealer: fa41d6b4 — blizzard-tecnica.com R12 cert twin, custom PE parser + multi-pass decoder 2026-07-28 lummastealer
- Phorpiex business-app masquerade downloader 2026-07-28 phorpiex
- ghostpulse: 833bffd0 — Qt5 x64 dropper with encrypted texture_mon.yaml payload, EaseUS masquerade 2026-07-28 ghostpulse
- acrstealer: 7620884e — Go 1.25.4 sibling with blizzard-tecnica.com cert (bridge to lummastealer cluster) 2026-07-28 acrstealer
- coinminer: f7abdaf8 — PyInstaller bootloader tenth sibling, Sep 2018 MSVC build, AES-encrypted overlay (1.96 MB) 2026-07-27 coinminer
- chromeloader-pulsar-rat c65fd4c2 — Pulsar v1.6.6.0 with defendnot+R77 rootkit stager, Lulsec Roblox masquerade 2026-07-27 chromeloader-pulsar-rat
- unclassified-danish-batch-ps-dropper — 93aec3da — Base64+XOR Monokrome fragments, Google Drive C2 2026-07-27 unclassified-danish-batch-ps-dropper
- 90d54589bfae 2026-07-27 lummastealer
- 8a2247462598 2026-07-27 unclassified-dotnet
- Lummastealer: 7b74bea7 — Go 1.25.4 PE32, Let's Encrypt R12-signed, PRNG C2 decoder 2026-07-27 lummastealer
- cace58e8cbbc 2026-07-26 stealc
- unclassified-dotnet-bitmap-stego-loader: 9ac1c1db — 283 embedded BMPs, clinical-trial masquerade 2026-07-26 unclassified-dotnet-bitmap-stego-loader
- 60996777bf4f — MinGW-w64 HTTPS Stage-1 Downloader / Reflective PE Loader 2026-07-26 unclassified-mingw64-https-stager
- avalancherunner: 485f73af — Fourth confirmed sibling, ParticlePlayground skin, no encrypted payload 2026-07-26 avalancherunner
- AgentTesla JScript Dropper — BL DOCUMENTS.JS 2026-07-26 agenttesla
- Deep Static Analysis — 38582041b3f7cc4e17afab411b38cde8d1d434a030a95cca2cc644c43fe8c1b6 2026-07-26 unclassified-dotnet-rijndael-md5-resource-loader
- unclassified-js-webdav-dropper: 2b1c5902 — 66-entry dictionary-lookup JScript dropper 2026-07-26 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 9665f822 — 62-entry dictionary, 624-char object name, WebDAV C2 94.159.113.79:8888 2026-07-25 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 2d0a9871 — 62-entry noise-dictionary, 877-char variable name, WebDAV C2 94.159.113.79:8888 2026-07-25 unclassified-js-webdav-dropper
- unclassified-js-german-locale-dropper — 2a336cba 2026-07-25 unclassified-js-german-locale-dropper
- unclassified-autoit-compiled: 29d3d471 — Proforma-invoice lure, 309 KB SCRIPT in .rsrc, Nov 2024 build 2026-07-25 unclassified-autoit-compiled
- Unclassified JS WebDAV Dropper: 27e35f3c — Dictionary lookup-table obfuscation (62 entries, 1,838-char variable name), PowerShell EncodedCommand wrapper, C2 94.159.113.79:8888 2026-07-25 unclassified-js-webdav-dropper
- Deep Analysis — 26666aa20903faa5a1c72b35c4207121fd3e924ad8eecb5d25dbd4cd3b3b8694 2026-07-25 unclassified-js-webdav-dropper
- Analysis — 25b576b7… (Unclassified JS WebDAV Dropper) 2026-07-25 unclassified-js-webdav-dropper
- 24c7c6cc3124 2026-07-25 xlabb-grabber
- NanoCore: 0eedf3a8 — Fifth confirmed Feb 2015 sibling, Backdoor.exe lure 2026-07-25 nanocore
- 93c5ae9a — JScript WebDAV Dropper (101st Sibling) 2026-07-24 unclassified-js-webdav-dropper
- Analysis: 17264699919263544.js (SHA-256: 91b12857bf...) 2026-07-24 unclassified-js-webdav-dropper
- unclassified-js-noise-base64-eval-dropper: 8e95d2b8 — second confirmed sibling, 2,292-byte noise string, 62-character payload 2026-07-24 unclassified-js-noise-base64-eval-dropper
- Analysis Report — 8ac4b873 2026-07-24 unclassified-js-webdav-dropper
- unclassified-autoit-compiled 8c88e736 — New_Order_List_Nov._2024.exe, overlay script placement 2026-07-23 unclassified-autoit-compiled
- 89fd643618c2 2026-07-23 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 86140a690cfd — 1.3 MB extreme-noise JScript, WebDAV C2 94.159.113.86:8888 2026-07-23 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 8323305a — 100-entry random-noise dictionary, direct WScript.Shell.run() execution, no PowerShell wrapper 2026-07-23 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — 82d78891aa19 2026-07-23 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 798fa958 — UPX-packed transport of 561c3ff6, 60.06% compression 2026-07-23 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: 77e8e3b2 — 53-variable sequential reassignment, fijnx variant, direct regsvr32 on 193.143.1.231 2026-07-23 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: f51f6323 — 100-entry random-noise dictionary, WebDAV C2 94.159.113.84:8888 2026-07-22 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — f346e80d14c2 2026-07-22 unclassified-js-webdav-dropper
- unclassified-dotnet-bitmap-stego-loader: f31920ba — Eighth confirmed sibling, bank/purchase-order GUI masquerade, mixed PNG+BMP carriers at 256×256/513×513 2026-07-22 unclassified-dotnet-bitmap-stego-loader
- unclassified-js-webdav-dropper: 77aff542 — 91st confirmed sibling, extreme variable-name padding (3,122 chars), rundll32 Entry on 94.159.113.86:8888 2026-07-22 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 561c3ff6 — DHL airway-bill + invoice hybrid lure, 352 KB SCRIPT in .rsrc 2026-07-22 unclassified-autoit-compiled
- Unclassified JS WebDAV Dropper: f2316aaf — Dictionary lookup-table obfuscation (62 entries), new C2 IP 94.159.113.86:8888, rundll32 Entry execution 2026-07-21 unclassified-js-webdav-dropper
- f01dca2e — JavaScript WebDAV Dropper (100-entry dictionary) 2026-07-21 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: edfb0e0a — JScript noise-variable concatenation + sequential reassignment hybrid 2026-07-21 unclassified-js-webdav-dropper
- unclassified-dotnet-tripledes-resource-loader: e8744da8 — ConfuserEx-obfuscated variant with AES-like inner payload 2026-07-21 unclassified-dotnet-tripledes-resource-loader
- unclassified-js-webdav-dropper: e6252c92 — 1.37 MB extreme-padded dictionary JScript, WebDAV C2 94.159.113.79 2026-07-21 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: e2568b43 — 100-entry random-noise JScript dictionary, anti-emulation timeout, WebDAV → regsvr32 2026-07-21 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: e0e66a94 — 52-variable sequential-reassignment JScript variant, 193.143.1.231:8888 2026-07-21 unclassified-js-webdav-dropper
- Vidar (d4b6905ef14c) 2026-07-21 vidar
- unclassified-autoit-compiled: e08d5bcef — RFQ engineering-document lure, 683 KB script in overlay 2026-07-20 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: ddf0c8bd — noise-variable concatenation obfuscation, no dictionary 2026-07-20 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: dca60b6b — DHL airway-bill lure, 493 KB encrypted SCRIPT resource, Dec 2024 build 2026-07-20 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: dbdb99f1 — 2,337-char noise-variable JScript dropper, PowerShell-rundll32 chain 2026-07-19 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: db9d07fd — Invoice-themed AutoItSC v3.3.8.1 with 690 KB encrypted SCRIPT resource (Nov 2024 build) 2026-07-19 unclassified-autoit-compiled
- unclassified-dotnet: db8c072b — DHL-lure dynamic-form generator with embedded RC4-style cipher demo 2026-07-19 unclassified-dotnet
- Unclassified JS WebDAV Dropper — d53e312c — 62-entry noise-key dictionary, new C2 94.159.113.79 2026-07-19 unclassified-js-webdav-dropper
- unclassified-js-german-locale-dropper: d3d22298 — JScript sequential-reassignment HTTP dropper with German LCID sandbox gate 2026-07-19 unclassified-js-german-locale-dropper
- unclassified-nsis-dropper: cbdff40b — inquiry_4387.exe, Deflate-compressed NSIS v3.06.1 with six encrypted payloads 2026-07-19 unclassified-nsis-dropper
- unclassified-js-noise-base64-eval-dropper: c83b7d57 — 1.09 MB noise-padded JScript with sequential variable-reassignment payload extraction 2026-07-19 unclassified-js-noise-base64-eval-dropper
- unclassified-dotnet: c9db49c9 — datalock phone-locker courseware masquerade 2026-07-18 unclassified-dotnet
- unclassified-autoit-compiled: c7eabe28 — LPO procurement lure, 751 KB script in overlay 2026-07-18 unclassified-autoit-compiled
- unclassified-autoit-compiled: c6c17d403f4d — Fifty-first confirmed sibling, Nov 2024 build, procurement-filename lure 2026-07-18 unclassified-autoit-compiled
- c4670e866e87 2026-07-18 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: c3985bb5 — AutoItSC PE32 with 30-byte XOR shellcode decrypting 'myriopodous' inner payload 2026-07-18 unclassified-autoit-compiled
- bf109c1f — Contract_Draft.exe — AutoIt dropper with CallWindowProc shellcode staging 2026-07-18 unattributed
- unclassified-js-webdav-dropper: be448b37 — 75th sibling, sequential reassignment eval, C2 193.143.1.231:8888 2026-07-18 unclassified-js-webdav-dropper
- 127c404a67f2d8c1673bd85759a1875b2e87055c506d769f1b7c699dbefb50bb 2026-07-17 unclassified-autoit-compiled
- unclassified-nsis-dropper: 11a56375 — Tenth confirmed sibling; unsigned BZip2 variant with multi-payload staging 2026-07-17 unclassified-nsis-dropper
- Deep Analysis Report — 0efed3b303e58e99f42f522e0c357c0b42d5999db3770f8bf43513869215c472 2026-07-17 unclassified-autoit-compiled (inner payload: agenttesla)
- unclassified-dotnet: 0e9cc5f81798 — Spanish student-evaluation CRUD app with stolen PuTTY cert masquerading as Adobe Reader 2026-07-17 unclassified-dotnet
- agenttesla: 0ce2a9be — Delphi VCL native stub → raw .NET metadata overlay → AgentTesla infostealer 2026-07-17 agenttesla
- coinminer: 983d2606 — PyInstaller bootloader ninth sibling, Sep 2018 MSVC build, AES-encrypted overlay (2.43 MB) 2026-07-16 coinminer
- unattributed: 89dd9159 — Python 3.13 embeddable runtime dropper with EnumDesktopWindows shellcode callback injection 2026-07-16 unattributed
- Unclassified JS WebDAV Dropper — 0e45e1b2 — JScript 62-entry noise-key dictionary, dailywebstats.com C2 2026-07-16 unclassified-js-webdav-dropper
- 0d3d6bb9 — .NET Framework WinForms checkers/draughts game masquerading as Shipping_docs.exe 2026-07-16 unclassified-dotnet
- unclassified-dotnet: 0bf2e649 — Parcheesi board game + Simple HSM Simulator masquerade 2026-07-16 unclassified-dotnet
- unclassified-dotnet: 0a0a24fc — Polish stock-charting app with stolen Simon Tatham certificate 2026-07-16 unclassified-dotnet
- lummastealer: 040e0d76 — PE32 with .rsrc icons, blizzard-tecnica.com cert, shared type names with d5647efd 2026-07-16 lummastealer
- unclassified-js-webdav-dropper: fe261d49 — 1,794-char extreme variable-name padding dictionary variant 2026-07-15 unclassified-js-webdav-dropper
- fbdd83ad649b 2026-07-15 unclassified-js-webdav-dropper
- chromeloader-pulsar-rat: 94682a96 — .NET stealer/RAT with Pulsar.Common v2.4.5.0, MessagePack C2, and multi-channel exfil 2026-07-15 chromeloader-pulsar-rat
- Unclassified JS WebDAV Dropper — 093a56f6 — JScript 62-entry noise-key dictionary, dailywebstats.com C2 2026-07-15 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper: 00a5ec55 — natural-language SET obfuscation with word-salad padding, 45.9.74.36:8888 2026-07-15 unclassified-js-webdav-dropper
- unclassified-dotnet: 000d931f — Third confirmed Pizzaria POS sibling, purchase-order lure 2026-07-15 unclassified-dotnet
- Unclassified JS WebDAV Dropper: fd437971 — 67th confirmed sibling, sequential variable-reassignment eval obfuscation 2026-07-14 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: fa8c6d74 — noise-variable JScript concat dialect 2026-07-14 unclassified-js-webdav-dropper
- f8dce7df01e6 2026-07-14 unclassified-js-webdav-dropper
- unclassified-dotnet: 495a9aa0 — JapaneseTrainer WinForms app repackaged as draft-file-request lure 2026-07-14 unclassified-dotnet
- unclassified-dotnet: 46c14f54 — OOP inheritance coursework app with purchase-order lure 2026-07-14 unclassified-dotnet
- 438fce55de8d 2026-07-14 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 2d720f57 — Purchase_Order_423737.exe, Charley-branded VS_VERSIONINFO, Sep 2024 build 2026-07-14 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: 4889c168 — 3-line shared-prefix batch, PowerShell wrapper + rundll32 entry 2026-07-13 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 434c5214 — natural-language batch variant, expanded word-salad padding 2026-07-13 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 42c82e1d — 659 KB overlay-script AutoItSC with New_Order.exe procurement lure 2026-07-13 unclassified-autoit-compiled
- 41d04ad59995 2026-07-13 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper 41472c6a — 36-entry noise-key dictionary, no PowerShell wrapper 2026-07-13 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 3f3540e1 — RFQ/ENQUIRY_ORDER tracking-code lure, 381 KB encrypted SCRIPT 2026-07-13 unclassified-autoit-compiled
- 3c63a3c06701 2026-07-13 unclassified-nsis-dropper
- unclassified-autoit-compiled: 3a538ef0 — DHL-document lure, 289 KB SCRIPT resource, Jul 2024 build 2026-07-12 unclassified-autoit-compiled
- unclassified-nsis-dropper: 3a13583c — Product-samples PDF masquerade, stride-6 Danish PowerShell, eight confirmed siblings 2026-07-12 unclassified-nsis-dropper
- Unclassified JS WebDAV Dropper — 385c2f0552de — Fifty-seventh confirmed sibling, 62-entry random-noise dictionary 2026-07-12 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 365235cd — shared-prefix ygfrlo dialect, payload 63.dll 2026-07-12 unclassified-js-webdav-dropper
- formbook: 3424a53f — purchase-order lure with C33JA stride-3 shellcode bootstrap 2026-07-12 formbook
- connectwise: 9477ccddefa6 — Apr 2025 ClickOnce bootstrapper, C2 104.236.198.16:8041 2026-07-11 connectwise
- unclassified-dotnet-crypter-loader: 5f54948e — Transponer masquerade, Unicode name obfuscation, 2.0 MB AES overlay, sixth confirmed sibling 2026-07-11 unclassified-dotnet-crypter-loader
- unclassified-dotnet: 5ea6b79d — Stolen-Tatham-cert pizza POS sibling 2026-07-11 unclassified-dotnet
- unclassified-dotnet: 5e34f10a — Spanish student-evaluation app with PO masquerade 2026-07-11 unclassified-dotnet
- unclassified-js-webdav-dropper: 5e170f1b — natural-language SET batch, WebDAV C2 45.9.74.32:8888, payload 209221036312347.dll, goto basketball 2026-07-11 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 33c0bfaf — 62-entry natural-language dictionary, cloudslimit.com:8888, PowerShell wrapper 2026-07-11 unclassified-js-webdav-dropper
- unclassified-dotnet-chess-engine: 337c323b — Second confirmed sibling, academic-document lure variant 2026-07-11 unclassified-dotnet-chess-engine
- darkcomet: b9b052df — Unpacked Delphi VCL RAT sibling, MSRSAAPP masquerade, identical v5.x command protocol 2026-07-10 darkcomet
- darkcomet: a3fa75fe — UPX-packed Delphi VCL RAT, MSRSAAPP masquerade, v5.x command prefix 2026-07-10 darkcomet
- 5bf25358 — .NET Framework Turkish Monopoly game with purchase-order double-extension masquerade 2026-07-10 unclassified-dotnet
- unclassified-js-webdav-dropper: 5931df0b — 62-entry compound-phrase dictionary, dailywebstats.com:8888 2026-07-10 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 58d9398a — 62-entry noise-key dictionary, dailywebstats.com:8888 2026-07-10 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 5833e797 — 1.11 MB SCRIPT resource, YASREF refinery engineering-document lure 2026-07-10 unclassified-autoit-compiled
- Unclassified AutoIt Compiled PE32 — 54ad2eac 2026-07-10 unclassified-autoit-compiled
- acrstealer: d353d849 — Eighth sibling, module JyUjBKWCTzoLKTp, no static C2 2026-07-09 acrstealer
- connectwise: b831f47e — Third confirmed sibling, C2 at 104.236.198.16:8041 2026-07-09 connectwise
- unclassified-dotnet: 54956960 — Lab4CSharp WinForms picture-viewer lab with CV lure and PictureViewer masquerade 2026-07-09 unclassified-dotnet
- unclassified-dotnet: 5335da6d — WinForms paint editor with Trif32 decoder (QUOTE lure) 2026-07-09 unclassified-dotnet
- unclassified-dotnet: 529fa495 — Karate_Club CRM sibling, .xlsx.exe double-extension masquerade 2026-07-09 unclassified-dotnet
- be44b0c3b1a1 2026-07-08 unclassified-batch-skip4-powershell-dropper
- unclassified-dotnet-bitmap-stego-loader: a497a066 — 21-bitmap maritime-lure sibling, Feb 2020 build 2026-07-08 unclassified-dotnet-bitmap-stego-loader
- unclassified-js-bitbucket-stego-dropper: 56ea37ef — JScript with fixed-delimiter concat obfuscation and image-steganography .NET loader 2026-07-08 unclassified-js-bitbucket-stego-dropper
- Unclassified Batch Self-Extract .NET Dropper: 51500e40 — Shipping-invoice BAT→PowerShell→ConfuserEx .NET chain with byte-reversed gzip payload 2026-07-08 unclassified-batch-selfextract-dotnet-dropper
- unclassified-js-webdav-dropper: 4fdfd354 — 62-entry shared-prefix polyglot, C2 45.9.74.13:8888, payload 515.dll 2026-07-08 unclassified-js-webdav-dropper
- 4f79aee0 — MicroMouseSimul .NET WinForms maze simulator (benign) 2026-07-08 unclassified-dotnet
- unclassified-js-webdav-dropper: 4f20ce5f — random-noise SET batch, WebDAV C2 45.9.74.36:8888, payload 1476539521452.dll 2026-07-08 unclassified-js-webdav-dropper
- unclassified-dotnet-crypter-loader: 4e31a886 — Holyaya masquerade, 473 KB AES overlay, fifth confirmed sibling 2026-07-08 unclassified-dotnet-crypter-loader
- unclassified-autoit-compiled: 4de51fe0 — T30WL8ASV permutation-XOR obfuscation, M31UY3G0 Caesar-1 hex shellcode, camellin/totten dual payload 2026-07-08 unclassified-autoit-compiled
- unclassified-dotnet: 4d780fea — Hadouken WinForms inventory CRUD app with MySQL backend and .bat.exe double-extension lure 2026-07-08 unclassified-dotnet
- unclassified-dotnet-chess-engine: 7d18d78c — Signed WinForMono bitboard chess engine with .pdf.exe double-extension lure 2026-07-07 unclassified-dotnet-chess-engine
- unclassified-autoit-compiled: 7c706df3 — REQUEST_FOR_QUOTATION.exe, July 2024 RFQ lure 2026-07-07 unclassified-autoit-compiled
- unclassified-dotnet: 7b3ef687 — Brazilian pizza-shop POS/CRM, no malicious payload 2026-07-07 unclassified-dotnet
- unclassified-dotnet: 4cce5506 — .NET WinForms checkers game with Security Descriptor Editor masquerade and .pif.exe double-extension lure 2026-07-07 unclassified-dotnet
- unclassified-autoit-compiled: 498f7bf3 — Caesar-3 hex-shellcode with 28-byte XOR key decrypting 229 KB inner PE 2026-07-07 unclassified-autoit-compiled
- unclassified-dotnet: 7a310c85 — KarateClub WinForms CRM repackaged as Purchase_Order.exe 2026-07-06 unclassified-dotnet
- Unclassified JS WebDAV Dropper — 77cbe0c4 — Random-noise dictionary keys, cloudslimit.com@8888, PowerShell -EncodedCommand wrapper 2026-07-06 unclassified-js-webdav-dropper
- unclassified-dotnet: 72d8e3b2 — Stolen-Tatham-cert k-means clustering GUI repackaged as university project lure 2026-07-05 unclassified-dotnet
- unclassified-dotnet: 72c4217f — Croatian-language AES/RSA cryptography coursework tool repackaged as SSLOS2024070909.exe 2026-07-05 unclassified-dotnet
- unclassified-dotnet: 724d94aa — AdvWinProgHW2 calculator with stolen Simon Tatham certificate 2026-07-05 unclassified-dotnet
- 708485983114 2026-07-05 unattributed
- Unclassified JS WebDAV Dropper — Batch Variant 2026-07-05 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 6f72a3a9 — 62-entry compound-phrase dictionary, dailywebstats.com:8888 2026-07-04 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper — 6f1d7c74 — 42nd sibling, polyglot JScript/batch with shared-prefix SET obfuscation 2026-07-04 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 6d9546a6 — 62-entry three-word compound-phrase dictionary, cloudslimit.com:8888 single-domain C2 2026-07-04 unclassified-js-webdav-dropper
- unclassified-dotnet: 6d114209 — Ivanov_WF_Paint WinForms editor with Trif32 decoder 2026-07-04 unclassified-dotnet
- unclassified-dotnet-protobuf-loader: 6cdc73c8 — Signed .NET RAT with protobuf-net C2, Smadav masquerade 2026-07-04 unclassified-dotnet-protobuf-loader
- unclassified-js-webdav-dropper: 6b7435afd70e — 62-entry noise-key dictionary, dailywebstats.com:8888 2026-07-04 unclassified-js-webdav-dropper
- iobit-driver-booster: a7a9205e — 7-Zip SFX installer for Driver Booster v3.4 2026-07-03 iobit-driver-booster
- unclassified-js-webdav-dropper: 69f29779 — 62-entry compound-phrase dictionary, cloudslimit.com C2 2026-07-03 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 68e48a8c — UPX-packed transport variant of salary-package .com masquerade 2026-07-03 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: 682bea06 — pure batch, natural-language SET obfuscation, 45.9.74.36:8888 2026-07-03 unclassified-js-webdav-dropper
- Deep Analysis — SHA-256 673e673800b807ec8ab291b464f62dc81576874956d702e7cfa152af61844421 2026-07-03 unclassified-dotnet-crypter-loader
- unclassified-autoit-compiled: 6718622d — Final_order.exe, AutoItSC → Caesar-3 hex shellcode → 19-byte XOR → AgentTesla 2026-07-03 unclassified-autoit-compiled
- Unclassified AutoIt Compiled PE32 — thirty-first confirmed sibling 2026-07-03 unclassified-autoit-compiled
- NanoCore RAT — 4121d69c (Backdoor.exe) 2026-07-03 nanocore
- SilverFox AV Teardown Driver-Dropper Variant 2026-07-03
- unclassified-autoit-compiled: 9e95f20b — procurement-BOQ lure with U30JZ3SO7 permutation-XOR obfuscation 2026-07-02 unclassified-autoit-compiled
- unclassified-dotnet: 644892e9 — Spanish RPG character generator masquerading as purchase order (confirmed sibling of ad301389) 2026-07-02 unclassified-dotnet
- unclassified-autoit-compiled: 6395396e — Spanish payment-lure with M30K3JL Caesar-2 obfuscation and 240 KB encrypted payload 2026-07-02 unclassified-autoit-compiled
- unclassified-dotnet: 9a40908c — FSC UI WinForms library second sibling (Zfio build), CV.pdf.exe lure 2026-07-01 unclassified-dotnet
- unclassified-js-webdav-dropper: 976dc607 — thirty-fourth sibling, batch natural-language SET obfuscation with word-salad padding 2026-07-01 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — 94686f16 — Three-word natural-language dictionary variant, cloudslimit.com payload 2026-07-01 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 941a189b — 601 KB overlay-script logistics-tracking lure, VS2010 linker 2026-07-01 unclassified-autoit-compiled
- unclassified-dotnet-crypter-loader: 931242f8 — AMSI-aware AES reflective loader with 2.38 MB encrypted overlay 2026-07-01 unclassified-dotnet-crypter-loader
- unclassified-autoit-compiled: bf0134ff — customer-remittance lure, 249 KB SCRIPT in .rsrc, MSVC 12.0 2026-06-30 unclassified-autoit-compiled
- AgentTesla: bee6e88e — .NET Native AOT-compiled infostealer, Albanian order-confirmation lure 2026-06-30 agenttesla
- unclassified-dotnet: bd60fe2a — RFQ-themed .NET assembly bundling binary-tutorial game + SSH remote-wget tool + JS combiner 2026-06-30 unclassified-dotnet
- unclassified-dotnet-crypter-loader 2026-06-30 unclassified-dotnet-crypter-loader
- unclassified-dotnet: b760c6f2 — .NET WinForms file manager masquerading as purchase-order lure 2026-06-30 unclassified-dotnet
- 92de8242 — GoldenCity .NET WinForms game masquerading as purchase-order PDF 2026-06-30 unclassified-dotnet
- unclassified-dotnet: 8d4d4300 — Node-graph WinForms editor, no payload 2026-06-30 unclassified-dotnet
- Unclassified JS WebDAV Dropper 2026-06-29 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: b612dd70 — 36-entry noise-key dictionary variant, 45.9.74.36:8888 C2 2026-06-29 unclassified-js-webdav-dropper
- unclassified-dotnet: b4814a17 — VD_Pacman + CalculatorWinForms dual-namespace masquerade, stolen Simon Tatham cert 2026-06-29 unclassified-dotnet
- unclassified-js-webdav-dropper: b32ea531 — Twenty-eighth sibling, natural-language SET batch, 45.9.74.36:8888 2026-06-29 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — Natural-Language SET Sibling 2026-06-29 unclassified-js-webdav-dropper
- Analysis Report — b0c43e946344c90398d20293a6e3356e9f922a6dcbe2b5134225cc94cf342412 2026-06-29 unclassified-js-rentry-telegram-dropper
- b094a2b61576 2026-06-29 unclassified-dotnet
- brooter: b04aa5d0 — Russian Delphi VCL brute-forcer with ICQ contact, SALES_INQUIRY.pdf.exe lure 2026-06-28 brooter
- b01c9133 — FREIGHT_INVOICE_80189CD_PDF.js 2026-06-28 unclassified-js-horus-dropper
- unclassified-autoit-compiled: b017d189 — AutoItSC shellcode→.NET infostealer, K30ZWMBJJ string obfuscation 2026-06-28 unclassified-autoit-compiled
- unclassified-dotnet: ad301389 — Spanish RPG character generator masquerading as purchase order 2026-06-28 unclassified-dotnet
- unclassified-js-webdav-dropper: aac0198b5 — 62-entry natural-language dictionary, cloudslimit.com:8888, PowerShell wrapper 2026-06-28 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper: aa8ff8b9 — 36-entry noise-key dictionary obfuscation, C2 45.9.74.36:8888 2026-06-27 unclassified-js-webdav-dropper
- Deep-dive — a9b5e7469c35f0cd7da326f9894d002a8bbe77377a11bbc03551dcbadab3b47a 2026-06-27 unclassified-dotnet
- Deep Analysis — a8beee89eb72 2026-06-27 unclassified-autoit-compiled
- formbook: a4cb4c76 — AutoIt dropper with PFMD87JH468RAUYH XOR key and shellcode bootstrap 2026-06-27 formbook
- unclassified-dotnet: a42443c8 — PrimeraVentana Spanish educational app repackaged as University-of-Bahrain project 2026-06-27 unclassified-dotnet
- unclassified-autoit-compiled: 891df280 — salary-package .com masquerade, 552 KB encrypted SCRIPT resource 2026-06-27 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: e11665cf — natural-language word-salad SET obfuscation, WebDAV C2 45.9.74.36:8888 2026-06-26 unclassified-js-webdav-dropper
- unclassified-dotnet: e04d46ff — FSC UI WinForms library with embedded SHA256 integrity hash, social-engineering filename 2026-06-26 unclassified-dotnet
- Unclassified JS WebDAV Dropper: df42ecf8 — Twentieth sibling, 62-entry noise-key dictionary on cloudslimit.com 2026-06-26 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: ded287fe — Bangladesh IT-park lure with 805 KB encrypted SCRIPT resource 2026-06-26 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: dc9b0407 — 19th sibling, shared-prefix batch SET obfuscation, rundll32 entry 2026-06-26 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: a435a37b — 36-entry noise-key dictionary variant, 45.9.74.36:8888 C2 2026-06-26 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: a3419c27a — 62-entry natural-language dictionary, cloudslimit.com:8888 2026-06-26 unclassified-js-webdav-dropper
- unclassified-dotnet: a1e6dc7a — Fourth stolen-Tatham-cert sibling, WinForms paint app masquerading as Adobe Reader 2026-06-26 unclassified-dotnet
- Unclassified JS WebDAV Dropper: dac5e0ee — 18th Confirmed Sibling 2026-06-25 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: d86e0912 — UPX-packed AUG_SOA.exe, 802 KB compiled AutoIt script in .rsrc 2026-06-25 unclassified-autoit-compiled
- unclassified-dotnet-bitmap-stego-loader: d4d106f8 — Sixth confirmed sibling, .text-section bitmap embedding, event-registration GUI masquerade 2026-06-25 unclassified-dotnet-bitmap-stego-loader
- Unclassified JS WebDAV Dropper: d36d84f2 — Seventeenth Confirmed Sibling 2026-06-25 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper: d1af0ff50c793f0f941bd1c38511dc87c050d42185f54ffac5861a31c7d2e20d 2026-06-25 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: d0124d62 — 36-entry dictionary JS, WebDAV C2 45.9.74.36:8888, payload 1783941328258.dll 2026-06-24 unclassified-js-webdav-dropper
- unclassified-nsis-dropper: cf9a061d — PDF-masquerade NSIS v3.02 with stride-8 Danish PowerShell + two encrypted PE payloads 2026-06-24 unclassified-nsis-dropper
- Unclassified JS WebDAV Dropper — cc90d6c — Alliterative dictionary obfuscation, dailywebstats.com C2 2026-06-24 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — Shared-Prefix SET Variant (Tenth Sibling) 2026-06-23 unclassified-js-webdav-dropper
- unclassified-js-s3-dropper: 2dbebbafe9d9 — XOR-obfuscated WScript→S3 HTTPS downloader sibling 2026-06-23 unclassified-js-s3-dropper
- Unclassified JS WebDAV Dropper: fb353965 — Ninth sibling, dual-domain C2 cloudslimit/cloudskimit 2026-06-22 unclassified-js-webdav-dropper
- unclassified-dotnet: c62e2921 — .NET PE32 with embedded NModbus library, TripleDES crypto, and reflective assembly loading 2026-06-22 unclassified-dotnet
- unclassified-dotnet-minesweeper-masquerade: c59a535b — .NET Framework Minesweeper game with Microsoft-themed version-info masquerade 2026-06-22 unclassified-dotnet-minesweeper-masquerade
- unclassified-dotnet: c4ee3a31081d — Spanish WinForms educational app repackaged with stolen Simon Tatham cert and HAWB logistics lure 2026-06-22 unclassified-dotnet
- Unclassified AutoIt Compiled PE32 — UPX-packed Invoice.exe variant 2026-06-21 unclassified-autoit-compiled
- unclassified-js-webdav-dropper — fa7e181d — dictionary-lookup JS dropper, shared C2 45.9.74.36:8888 2026-06-21 unclassified-js-webdav-dropper
- unclassified-rust-dropper-2024: f97c10fc — Industrial RFQ lure, tokio+reqwest payload fetch, NtWriteVirtualMemory injection 2026-06-21 unclassified-rust-dropper-2024
- unclassified-nsis-dropper: f7f089f7 — Danish-character-skip PowerShell + four encrypted PE payload NSIS SFX 2026-06-21 unclassified-nsis-dropper
- unclassified-dotnet: f7c4caea — ReichUI WinForms library repackaged as purchase-order lure 2026-06-21 unclassified-dotnet
- unclassified-autoit-compiled: f527ce01 — 1012024.exe, 413 KB SCRIPT, numeric-date lure 2026-06-20 unclassified-autoit-compiled
- unclassified-autoit-compiled: f51bc678 — FDA.exe, 196 KB SCRIPT, PDF-icon masquerade 2026-06-20 unclassified-autoit-compiled
- unclassified-dotnet-transmock-masquerade: f3bc22f6 — .NET PE masquerading as TransMock utility with WinHTTP downloader and encrypted payload staging 2026-06-20 unclassified-dotnet-transmock-masquerade
- Unclassified AutoIt Compiled PE32: f3a48a8c — PO lure, 313 KB encrypted script, PCRE runtime 2026-06-20 unclassified-autoit-compiled
- unclassified-autoit-compiled: f346b7e9 — 659 KB overlay-script PO lure, Jan 2012 AutoItSC v3.3.8.1 2026-06-20 unclassified-autoit-compiled
- unclassified-autoit-compiled: f2be9e06 — PO_#86637.exe, 417 KB SCRIPT, PCRE regex library 2026-06-19 unclassified-autoit-compiled
- unclassified-dotnet-bitmap-stego-loader: f230118d — engineering PO lure with AES+Deflate bitmap payload chain 2026-06-19 unclassified-dotnet-bitmap-stego-loader
- Unclassified AutoIt Compiled PE32: f0059bee — 932 KB SCRIPT resource, procurement lure 2026-06-19 unclassified-autoit-compiled
- unclassified-autoit-compiled: ef71e0f6 — AutoItSC PE32 with 186 KB encrypted SCRIPT resource, 'Public Holiday Notice' payroll lure 2026-06-19 unclassified-autoit-compiled
- unclassified-dotnet: eea0dcbc — Stolen-cert attendance tracker masquerading as payment document 2026-06-19 unclassified-dotnet
- unclassified-js-webdav-dropper: ed6b2cd3 — Sixth confirmed sibling, labzf-prefix SET obfuscation, rundll32 entry execution 2026-06-19 unclassified-js-webdav-dropper
- unclassified-batch-string-slice-dropper: eae731d3 — FTSP.zip Python stager, UTF-16 LE variant with corrected %USERPROFILE% expansion 2026-06-19 unclassified-batch-string-slice-dropper
- petpack: ea56cf43d33b — AES-managed .NET loader, Serbian banking lure, timestamped Aug 2024 2026-06-18 petpack-dotnet
- unclassified-dotnet: e7aaacbb — .NET Framework educational crypto lab repackaged as DHL shipping lure 2026-06-18 unclassified-dotnet
- Unclassified JS WebDAV Dropper — Shared-Prefix SET Variant 2026-06-18 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — e6ebae6a — JScript dictionary obfuscation + WebDAV regsvr32 chain 2026-06-18 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 6cc26f7c — UPX-packed AutoItSC shipping-lure, 241 KB SCRIPT in .rsrc 2026-06-18 unclassified-autoit-compiled
- unclassified-autoit-compiled: 1d0834e7 — Greek invoice-lure, 221 KB SCRIPT, plain AutoItSC 2026-06-18 unclassified-autoit-compiled
- Unclassified JS WebDAV Dropper — Batch Variant 2026-06-17 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: ff84806a — Jan 2012 AutoItSC v3.3.8.1, script-in-overlay variant 2026-06-17 unclassified-autoit-compiled
- unclassified-batch-string-slice-dropper: aa443a5285 — FTSP.zip Python stager with 64-char string-slice obfuscation 2026-06-17 unclassified-batch-string-slice-dropper
- unclassified-go-pe64: 9665ccc9 — Go 1.25.1 PE64+ with fake WindowsSoundDiagnostics source-path masquerade 2026-06-17 unclassified-go-pe64
- Unclassified AutoIt Compiled PE32 — Invoice.exe sibling 2026-06-17 unclassified-autoit-compiled
- remusstealer: 2b2293a0 — Protector Lab (plab) AES-GCM overlay packer, May 2026 MinGW-w64 x64 2026-06-17 remusstealer
- avalancherunner: f7352bc1 — Third confirmed sibling, bomb-defusal skin, PDF-masquerade version info, no encrypted CLR payload 2026-06-16 avalancherunner
- Deep Analysis — f6b5bdd5958eefc7f7e595ee8e91c2407193226acad0bfa939f3a1a42cf08396 2026-06-16 unclassified-dotnet-bitmap-stego-loader
- unclassified-pe64-clipper: af6e1f46 — MinGW-w64 infostealer with wallet regex, Telegram user ID, and screenshot capture 2026-06-16 unclassified-pe64-clipper
- unclassified-autoit-compiled: ac2ca060 — AutoItSC PE32 with 802 KB encrypted SCRIPT resource, 'AUG_SOA' business lure 2026-06-16 unclassified-autoit-compiled
- test: 7a2c8630 — MalwareBazaar test-upload ZIP with trivial Python payload 2026-06-16 test
- remcos — v1.7 Pro, Jan 2017 — 803-byte SETTINGS RCData variant 2026-06-16 remcos
- 341165a42115 2026-06-16 hippamsascom
- unclassified-js-s3-dropper: 26afa8d1 — Plain-text WScript→S3 HTTPS downloader with SSL cert-error bypass 2026-06-16 unclassified-js-s3-dropper
- coinminer: 058ab625 — PyInstaller bootloader eighth sibling, Sep 2018 MSVC build, AES-encrypted overlay (2.76 MB) 2026-06-16 coinminer
- uniqfile: e79a525e — MinGW-w64 x86 .rdata payload with XOR-loop reflective loader 2026-06-15 uniqfile
- asyncrat: e57d8c5a — VIN88APP.exe sibling, ~28 KB builder-default stripped build 2026-06-15 asyncrat
- hippamsascom: c20bbb80 — Olson Group masquerade, 502 semantic export flood, self-loading dropper 2026-06-15 hippamsascom
- poabu-inno-dropper: bb3fd6cd — Authenticode-signed Inno Setup 6.7.0 masquerading as contact-indexing service 2026-06-15 poabu-inno-dropper
- wannacry: ad4df92f — WannaCry v2.0 sibling, kill-switch wea.com, service name 2.0 2026-06-15 wannacry
- 8eddf076bf8b 2026-06-15 hippamsascom
- asgardprotector: 87a158f2 — Signed IExpress SFX dropper with stolen FileZilla cert, AutoIt3 + Easter.a3x 2026-06-15 asgardprotector
- connectwise: 7145e8 — Self-contained MSI-based ScreenConnect client installer, hardcoded C2 at 134.122.4.2:8041 2026-06-15 connectwise
- Phorpiex x64 CPlApplet PNG Payload Dropper 2026-06-15 phorpiex
- asyncrat: 2b125840 — Google Chrome masquerade, builder-default MessagePack C2 client 2026-06-15 asyncrat
- 177bfc846a77 2026-06-15 netsupport-inno-dropper
- Phorpiex Downloader Sibling — 13/14/peinf/xmr/xmrget Chain, Earliest Build 2026-06-14 phorpiex
- gh0st: e65bbcad — Qt6 x64 RAT with encrypted payload blob, March 2026 2026-06-14 gh0st
- Unclassified JS WebDAV Dropper 2026-06-14 unclassified-js-webdav-dropper
- xenorat: c50bb7b4 — au88-branded v0.0.2.0 sibling with LZNT1 async C2 2026-06-14 xenorat
- unclassified-danish-batch-ps-dropper: 402879ff4b36 — Character-skip BAT→PowerShell downloader, Italian C2 2026-06-14 unclassified-danish-batch-ps-dropper
- 028301d695ca 2026-06-14 unclassified-python-ngrok-rat
- d0ca14b3ad12 2026-06-13 letsdiskusscom
- 9dc2cded28a0 2026-06-13 letsdiskusscom
- 54e64e: 7aed04ab — Signed IExpress SFX with AutoIt3 payload + batch variable-expansion reconstruction 2026-06-13 54e64e
- 54e64e: 6e0ef3af — MSVC x64 XMM-loader with 2.8 MB encrypted .data payload 2026-06-13 54e64e
- Remcos RAT: 6114904c — v1.7 Pro sibling, 616-byte SETTINGS RCData, no version info 2026-06-13 remcos
- 247b54b524dc 2026-06-13 letsdiskusscom
- 404356dbc85c — ALL SHIPPING DOC DRAFT BL.JS 2026-06-12 unclassified-js-dropper
- Vidar (3799d1f74d95) 2026-06-12 vidar
- coinminer: fbfd2d94 — 2.37 MB PyInstaller sibling, Sep 2018 cluster, 89% zlib overlay 2026-06-11 coinminer
- unclassified-dotnet-bitmap-stego-loader: f74d8a51 — 984 KB fleet-maintenance masquerade with SOAP/HTTP reference 2026-06-11 unclassified-dotnet-bitmap-stego-loader
- Unclassified .NET Bitmap-Stego Loader: db0d6bc0 — Purchase Order.exe, May 2022 build 2026-06-11 unclassified-dotnet-bitmap-stego-loader
- nanocore: d065ebea — VB.NET ConfuserEx sibling, NanoCore v1.2.2.0 RAT (hotro.exe) 2026-06-11 nanocore
- 54e64e: 8017acd5 — Go 1.25.4 signed PE64+ with fabricated godaddy.com/WE1 Authenticode 2026-06-11 54e64e
- nanocore: 48c8e8a2 — VB.NET ConfuserEx sibling, NanoCore v1.2.2.0 RAT 2026-06-11 nanocore
- phorpiex: 32f29422 — Earliest-build thin MSVC9 downloader sibling (4-payload chain, grab.exe fallback) 2026-06-11 phorpiex
- silentnet: dbe586b5 — Zig 0.12.0 PE64 launcher with XOR-obfuscated C2 and TLS 1.3 HTTP client 2026-06-10 silentnet
- gerador-loader: 55db7544 — Brazilian MSVC loader stub, Defender exclusion + HTTP cradle 2026-06-10 gerador-loader
- 4978e16a7f6b 2026-06-10 unclassified-nsis-dropper
- Phorpiex Downloader Sibling — peinf/xmr/xmrget Chain 2026-06-10 phorpiex
- overwolf-teamspeak-helper: 2d2a251a — Signed MSVC C++ PE32+ x64, benign application mis-tagged in MalwareBazaar 2026-06-10 overwolf-teamspeak-helper
- silverfox: 17d6415d — DLL side-loader masquerading as MaxxAudioAPOShell64 with anti-VM gates 2026-06-10
- wannacry: 16fdcfbc — May 2017 outbreak DLL, kill-switch + EternalBlue + 27-language ransom note ZIP 2026-06-10 wannacry
- unclassified-dotnet-crypter-loader: 07835853 — .NET Framework 4.0 reflective loader with AES-GZip-Base64 manifest-resource decryption and native API P/Invoke 2026-06-10 unclassified-dotnet-crypter-loader
- unclassified-pe32-clipper: f936b99e — MSVC C++ Telegram-relayed crypto clipper with registry persistence 2026-06-09 unclassified-pe32-clipper
- acrstealer: d5655568 — Fourth signed Go 1.26.2 sibling, module JPYhJIzovpOdAaG, custom PE parser + multi-pass decoder 2026-06-09 acrstealer
- d52f85: 2fb095b1 — CS2 external cheat 'Cheetah' dropped by Amadey 2026-06-09 d52f85
- avalancherunner: 1a38a948 — Uzbek-languaged .NET game-masquerade loader with encrypted CLR resource payload 2026-06-09 avalancherunner
- zenconnekt: cd97c264 — Go PE64+ modular RAT, signed, C2 over TLS+WebSocket, Microsoft masquerade 2026-06-08 zenconnekt
- coinminer: b4cc27e3 — Smallest PyInstaller bootloader sibling, 630 KB, Python 2.7 payload 2026-06-08 coinminer
- 9d2ca3 Go Cluster: 389e1ccf — EclipseV2.exe, x64 sibling with GoDaddy-masquerade cert 2026-06-08 9d2ca3
- phorpiex: bb77ef06 — $500 USD sextortion spam bot, earliest known May-22 campaign build 2026-06-07 phorpiex
- unclassified-go-pe64: 82ee3cdd — Go 1.25.4 signed PE64 with multi-pass payload decryption and in-memory PE loader 2026-06-07 unclassified-go-pe64
- connectwise: 81adbf9a — Authenticode-backed ClickOnce runner for ScreenConnect remote-access deployment 2026-06-07 connectwise
- quasar 2026-06-07 quasar
- phorpiex: 025f5798 — MSVC9 thin HTTP downloader, earlier build (13:06 UTC) missing 15.exe payload 2026-06-07 phorpiex
- unclassified-pe32-nfe-loader: ded59ec4 — MinGW AES-like dropper, Brazilian NFe lure 2026-06-06 unclassified-pe32-nfe-loader
- unclassified-pe32-nfe-loader: ac20be18 — 4 KB MinGW launcher stub for core.dll 2026-06-06 unclassified-pe32-nfe-loader
- xenorat: 6133cd0b — .NET Framework 4.8 RAT, LZNT1 compression, async C2 node architecture 2026-06-06 xenorat
- coinminer: 359fcf01 — PyInstaller bootloader sibling, Sep 2018 MSVC build, AES-encrypted overlay with weak QWERTY key 2026-06-06 coinminer
- hippamsascom: 1cf56da3 — Mayer-Ondricka CSS matrix self-loading dropper 2026-06-06 hippamsascom
- quasar 2026-06-06 quasar
- remcos: c6193af6 — v1.7 Pro, enlarged 593-byte SETTINGS RCData 2026-06-05 remcos
- 4bf14434ef61 2026-06-05 unclassified-dotnet-bitmap-stego-loader
- silverfox: e772de93 — C x64 stub with Sangfor EDR masquerade and dual-lang .rsrc icon set 2026-06-04 silverfox
- remcos: 5a1e57f7b0 — v1.7 Pro sibling, 531-byte SETTINGS RCData 2026-06-04 remcos
- silverfox: 452e085f — MSVC C++ x64 process hollowing injector with LZSS decompressor and privilege escalation 2026-06-04 silverfox
- 027aeb2eb483 2026-06-04 unclassified-pe32
- cae0056acc2f 2026-06-03 unclassified-batch-powershell-dropper
- phorpiex: 6b8527a7 — MSVC9 thin HTTP downloader with mutex-gated payload branching 2026-06-03 phorpiex
- remcos: 0f723826 — v1.7 Pro, Jan 2017, no packer 2026-06-03 remcos
- nanocore: fe81691f — VB.NET ConfuserEx dropper, NanoCore v1.2.2.0 RAT 2026-06-02 nanocore
- 54e64e: c8db13c1 — UPX-packed x64 sibling with modified packer, zero readable strings, Amadey-dropper pedigree 2026-06-02 54e64e
- 9d2ca3: a7b9f3dd — Go 1.25.4 PE64 infostealer with randomized module path and fabricated Authenticode 2026-06-02 9d2ca3
- coinminer: 640ed5b5 — PyInstaller bootloader sibling, 735 KB, September 2018 cluster 2026-06-02 coinminer
- coinminer: 5047235c — PyInstaller bootloader sibling with appended sub-PE, 1.8 MB overlay 2026-06-02 coinminer
- unclassified-js-dropper: 0e4141aa — WScript→PowerShell→.NET assembly loader with debugger/sandbox gate 2026-06-02 unclassified-js-dropper
- maskgramstealer: abeaa63b — MinGW-w64 PE64 infostealer with runtime API resolution and wallet-seed regex 2026-06-01 maskgramstealer
- 54e64e: 3b13b28c — MSVC C++ certpert dropper with fake diagnostic masquerade, Defender exclusion, and HTTP payload fetch 2026-06-01 54e64e
- 9d2ca3: 2d39ed5e — Amadey-dropper, MinGW-w64 x64 with 2.55 MB encrypted .data payload 2026-06-01 9d2ca3
- lummastealer: e03dd36f — x64 sibling, fraudulent cert, runtime API decoding 2026-05-31 lummastealer
- ayrseushop: 5a5b3373 — MSVC x64 infostealer with runtime string-decryption, clipboard+screenshot harvesting 2026-05-31 ayrseushop
- 0c9e772d8730 2026-05-31 hippamsascom
- pyinstaller-pyarmor-dropper: d297973f — PyInstaller single-file bootloader with PyArmor-obfuscated Python 3.13 payload 2026-05-30 pyinstaller-pyarmor-dropper
- dolphin: ca6be0bf — Rust x64 polymorphic RAT/stealer with 80+ task types, WebSocket C2, masquerading as NVIDIA Display Container LS 2026-05-30 dolphin
- silverfox: 82d42551 — Lean C-based x64 stub (50K) sharing stream-cipher constants and thunk dispatch 2026-05-30 silverfox
- menomoushop: 3aca18df — Go 1.25.4 PE64 infostealer, Authenticode signed CN=maybe.us, randomized function names 2026-05-30 menomoushop
- 129ef9250b91 2026-05-30 spamita
- euone: 0c9236cf — Delphi VCL installer with embedded 202 KB RCData payload 2026-05-30 euone
- acrstealer: f93d8d79 — Signed Go 1.26.2 sibling with stripped .rsrc, module gesiimdPYMojqEh 2026-05-29 acrstealer
- silverfox: ed1a0047 — Rust x64 dropper with LZSS payload extraction and ntdll unhooking 2026-05-29 silverfox
- prometei: e6ce5dd2d422 — UPX-packed ELF64 systemd dropper, HTTP CGI C2 2026-05-29 prometei
- lummastealer: d5647efd — Go 1.25.4 signed PE32, no .rsrc, certificate www.sjabr.org 2026-05-29 lummastealer
- neuralpulsecore5sbs: 47a2204d — First x64 sibling, Sectigo-signed, no hardcoded C2 2026-05-29 neuralpulsecore5sbs
- Deep Analysis: 1bfebf79c24d0813eb39fec74637d52b008188812631a4f666a59fae7c0cef2c 2026-05-29 acrstealer
- acrstealer: 16a4344d — Signed Go 1.26.2 PE32, module hlHtIOAoWQhvCrI, cert CN=me.muz.li 2026-05-29 acrstealer
- asgardprotector: d59dc2f2 — IExpress SFX dropper embedding AutoIt3 + compiled A3X script 2026-05-27 asgardprotector
- asgardprotector: d364a2f6 — IExpress SFX dropper embedding AutoIt3 + Dayton.a3x script 2026-05-27 asgardprotector
- acrstealer: c577c6c8 — Signed Go 1.26.2 PE32 sibling, randomized module PfeYrYvazVUGgZq 2026-05-27 acrstealer
- acrstealer: ef262340 — Go 1.18.5 tenth sibling, self-signed atom.hutsell.com cert 2026-05-26 acrstealer
- coinminer: c4ac7426 — Signed 7-Zip SFX dropper, VC++ redist masquerade, password-protected archive 2026-05-26 coinminer
- coinminer: 801fbba1 — PyInstaller bootloader, Sep 2018 MSVC build, embedded Python payload 2026-05-26 coinminer
- unclassified-js-webdav-dropper: 771c8752 — 90th confirmed sibling, hybrid reassignment+concatenation dialect, davww7root typo 2026-05-26 unclassified-js-webdav-dropper
- acrstealer: 6871848b — Signed Go 1.26.2 PE32, randomized module names, C2 5.252.155.72 2026-05-26 acrstealer
- meterpreter: 5da21aa2 — x64 reverse_tcp stager with inline sockaddr, zero IAT 2026-05-26 meterpreter
- 563db9705ede 2026-05-26 unclassified-js-webdav-dropper
- coinminer: 39b67a79 — PyInstaller bootloader sibling, 4.3 MB with 94% zlib overlay 2026-05-26 coinminer
- chacha8: svchost.exe — ChaCha20 stream-cipher file encryptor with in-place overwrite, no C2 2026-05-26 chacha8
- nfedigitalcom - ffdd7105 nfedigitalcom
- Unclassified JS WebDAV Dropper — Sibling 68 unclassified-js-webdav-dropper
- gh0strat/valleyrat — fdaabbf7 — Inno Setup 6.5.7.1 Doubao masquerade dropper gh0strat
- unclassified-dotnet-bee-themed-rasterizer: fc944b54 — shipping-document masquerade, bee-themed internal naming, static-only analysis unclassified-dotnet-bee-themed-rasterizer
- fbc07658954f valleyrat
- fb5bc5438cc0 unclassified-autoit-compiled
- faa32ac2a1af
- sunwukong — fa16b64a — Semantic export obfuscation and PEB-walking API resolution sunwukong
- Deep-Dive Report — f9a1fc01119ed1cc7a5464cc4df2d3f0dea09f8227c6ba101c77c73f6c379214 unclassified-dotnet
- f618a8619ab4 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: f170f5a9 — Seventh sibling, natural-language SET obfuscation, WebDAV C2 45.9.74.36:8888 unclassified-js-webdav-dropper
- NanoCore: f017a517 — EMU.exe emulator masquerade, 1.2.2.0 builder, 90 KB encrypted RCData nanocore
- ef48ae9e7d02 unclassified-dotnet-native-aot-loader
- Pay2Key Ransomware
- Phorpiex sextortion spam bot sibling — MSVCR90 stub, $800 variant, updated Chrome UA phorpiex
- unclassified-batch-powershell-dropper: eda47a53 — pastefy/GitLab variant, Sostsenrer2 C2 unclassified-batch-powershell-dropper
- ec95bcf427c8 unclassified-pe64-modular-builder
- ebceb9dbc06f mirai
- eba13078dea9 unclassified-js-cjk-stego-dropper
- LummaStealer: eaa52e19 — x64 morph, 71-function namespace, 1 MB null-padded overlay lummastealer
- e9e82d14538b unclassified-js-webdav-dropper
- unclassified-destructive-batch: e844c4cb — 982-byte batch script masquerading as a DDoS tool that destroys system32 unclassified-destructive-batch
- unclassified-dotnet: e816172f — TimeToRun C# snippet compiler, benign developer tool unclassified-dotnet
- unclassified-autoit-compiled: e5647a2d — 1.36 MB invoice-lure with 710 KB encrypted script in overlay unclassified-autoit-compiled
- e535cab50e81 acrstealer
- 54e64e: e14cb7f3 — .NET ILRepack crypter with AES-Z85-JC-1-2 decryptor, MES WCF C2 54e64e
- e0de4e3c9dee phorpiex
- unclassified-js-webdav-dropper unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper: dc76a67d — 1,255-char variable noise-key dictionary unclassified-js-webdav-dropper
- da02fd0723ca coinminer
- d9c0bc24413e unclassified-dotnet-whisper
- remcos v1.7 Pro — d9950b15 — 480-byte SETTINGS, no VS_VERSIONINFO, plain Backdoor.exe remcos
- d990bd1b64d3 unclassified-autoit-compiled
- d90baa30d713 unclassified-js-webdav-dropper
- d69d4497aa86 phorpiex
- d693570c4c08 tofsee
- d5b11a1cb3ad unclassified-pe32-dotnet
- eu0file: d46e2b49 — False positive: legitimate Windows 8.1 mspaint.exe mis-tagged in gcleaner distribution context eu0file
- d3bb6eb48a3f asyncrat
- phorpiex sextortion spam bot — mutex t8 phorpiex
- ceacabb454c2 unclassified-js-webdav-dropper
- ce07d963d3c5 unclassified-dotnet-strong-masquerade
- unclassified-js-webdav-dropper ccb2d007 — Thirteenth sibling unclassified-js-webdav-dropper
- cca7d56dffd8 unclassified-autoit-compiled
- 54e64e (misattributed): cc4aa789 — Go 1.25.4 x64 signed infostealer, randomized main functions, no hardcoded C2 54e64e
- cbc590012eba phorpiex
- cbadab4db7d5
- cb5d302f6577 unclassified-js-webdav-dropper
- unclassified-dotnet: cae7ac1dc419 — PrimeraVentana Spanish educational app repackaged with stolen Simon Tatham (PuTTY) Authenticode certificate unclassified-dotnet
- c9c81f5be1bd unclassified-autoit-compiled
- Deep Analysis — c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36 unclassified-batch-powershell-dropper
- unclassified-autoit-compiled: c80ef443 — UPX-packed RFQ lure, 220 KB SCRIPT resource unclassified-autoit-compiled
- letsdiskusscom — c485dd9c6d810f36618315d661ecb801f4ef8d44ef9946876a4649ed8c23c15e letsdiskusscom
- phorpiex: c3b1b4e4 — MSVC9 sextortion spam bot, $800 variant, mutex t5 phorpiex
- unclassified-autoit-compiled: c310cb2e — UPX-packed duplicate of e5647a2d invoice-lure unclassified-autoit-compiled
- Pay2Key: c1a201cf — Nov 2025 MSVC 14.16 sibling, unpacked, 4-icon .rsrc pay2key
- c075aeba57f0 letsdiskusscom
- silverfox: beb3a9d9 — Authenticode-signed C x64 sibling with LZSS .rdata payload and process enumeration silverfox
- unclassified-js-webdav-dropper: be58d381 — Thirty-first confirmed sibling, 36-entry noise-key dictionary, WebDAV C2 45.9.74.36:8888 unclassified-js-webdav-dropper
- be172014 — JScript WebDAV Dropper with Dictionary-Lookup Obfuscation unclassified-js-dropper
- AFK Stealer: bd6dead7f5a0ec51 — Fourth confirmed sibling, expanded RAT surface (WebSocket C2, SOCKS5 proxy, screen streaming, keylogging, token duplication) afk-stealer
- unclassified-nsis-dropper: b3fb616d — "Revised_PI_2024.exe", stride-6 Danish character-skip PowerShell unclassified-nsis-dropper
- letsdiskusscom — b23bb560a20c587c6888813fc06a53d4eac46af78a3813fdeefa6b6667176024 letsdiskusscom
- b221a625be88 phorpiex
- Deep Dive: ae2e9acd01f8 — letsdiskusscom (tenth sibling) letsdiskusscom
- unclassified-js-webdav-dropper: ade6cf68 — 36-entry noise-key dictionary, WebDAV C2 45.9.74.36:8888, payload 3118252697895.dll unclassified-js-webdav-dropper
- accd2ccd2be4
- abf498a10e71 asyncrat
- aa4d237c7a9b
- connectwise: aa116a62 — tenth confirmed sibling, new C2 193.26.115.231:8041, Oct 2024 cert timestamp connectwise
- a94a77a31e66
- unclassified-js-pptx-dropper: a8c581f2 — javascript-obfuscator RC4 dropper fetching PowerShell from bare IP unclassified-js-pptx-dropper
- unclassified-go-pe64: a5520aba — Go PE64+ signed with GoDaddy DV cert, MD5/SHA256 crypto routines, zero static C2 unclassified-go-pe64
- AsyncRAT: a41d0d35 — System Informer masquerade, stripped build (no keylogger, no plugins) asyncrat
- Unclassified JS WebDAV Dropper unclassified-js-webdav-dropper
- a1943a9a0da7 uniqfile
- 9f7ee895f028 unclassified-go-pe32
- unclassified-msvc-browser-credential-harvester unclassified-msvc-browser-credential-harvester
- lummastealer: 9ca2ebb8 — x64 morph, 71-function namespace, placeholder xxx.com cert, 726 KB null-padded overlay lummastealer
- unclassified-nsis-dropper: 9c43b920 — "Documents.exe", NSIS v3.02 with six-file embedded payload unclassified-nsis-dropper
- Unclassified JS WebDAV Dropper unclassified-js-webdav-dropper
- 9a3c18be3957 hippamsascom
- 99e5d5d8e7e0 unclassified-dotnet-inventory-app
- 9829594064f4
- 9410374bb9cc ghostpulse
- blackmatter (blackmatter cluster, 26th sibling) blackmatter
- unattributed: 93857f30 — Truncated Go PE64+ x64 (276 KB of claimed 2.1 MB image, third confirmed sibling) unattributed
- blackmatter (blackmatter cluster): 92fc7f45d496 — 28th sibling, PE checksum 0x27b0a blackmatter
- 92ce4217922a unclassified-js-webdav-dropper
- 8f28849296f4 9d2ca3
- Unclassified JS WebDAV Dropper — Sequential Variable-Reassignment Variant with Bracket-Notation Eval Dispatch unclassified-js-webdav-dropper
- unattributed (blackmatter cluster, 19th sibling) unattributed
- 8821c53f677a1d84b8389c328e0e3d5966d320eece827fef890d217936685e9c unclassified-js-webdav-dropper
- unattributed (blackmatter cluster, 20th sibling) unattributed
- letsdiskusscom 7d9ac86521aba5d8989dd21ed08ab3b138c7aeb4dd41bf8566c10d3d240f55a1 report letsdiskusscom
- Unclassified AutoIt Compiled PE32: 7bfa4723 — Purchase-order lure, 768 KB encrypted script in overlay unclassified-autoit-compiled
- 796a371d25a0 us0file
- unclassified-nsis-dropper: 78c5e8ca — "Ref_7021929821US20240709031221650.exe", stride-6 Danish character-skip PowerShell unclassified-nsis-dropper
- 7768873f4b7e unclassified-autoit-compiled
- unattributed: 771c7952 — .NET Framework semantic-name masquerade loader, HttpClient+GZip reflective assembly unattributed
- 763ae850f760 unclassified-autoit-compiled
- Phorpiex spam dropper — screensaver-masqueraded MSVCR90 stub with .rsrc payload staging phorpiex
- unattributed: 73d7c8e5 — Delphi VCL purchase-order masquerade, no observable payload unattributed
- 7317e559dedf unclassified-autoit-compiled
- phorpiex sextortion spam bot — 724ec6b8 — mutex t10, 10th confirmed $800 sibling phorpiex
- 7213e78737d5
- letsdiskusscom: 71e6cb9e — Twenty-seventh confirmed sibling, Update_8.js, numbered-suffix poem steganography letsdiskusscom
- 7129076f2b64 unclassified-js-cjk-stego-dropper
- 710f15302859 remotepe
- orderreshop: 6f6f0525 — Go infostealer with custom PE parser and multi-pass string decoder orderreshop
- 6f4de3f972e1
- 6e5e5715059b unclassified-js-webdav-dropper
- 6bc4e16d2dee unclassified-dotnet
- coinminer (mislabelled): 6b881268 — PyInstaller ftpcrack sibling, 488 KB, 10 zlib streams, AES-encrypted overlay coinminer
- 6b33d2019626 remotepe
- unclassified-dotnet: 6a53c56172ce — PrimeraVentana Spanish educational app repackaged with LUA Client masquerade unclassified-dotnet
- phorpiex sextortion spam bot $800 variant mutex t1 phorpiex
- ratonrat: 667f1f97d015 — .NET Framework 4.x full-spectrum RAT, HVNC + browser theft + ransomware module ratonrat
- avalancherunner: 64e2d169 — TT01650Q tracking-code lure, encrypted payload restored, hardcoded SHA-256 hash avalancherunner
- 642ecaab44fc hijackloader
- 630202e68560 hippamsascom
- 62e040a32aac remotepe
- 624f52cc31cd acrstealer
- 61c1041120dd unclassified-dotnet
- unclassified-nsis-dropper: 600d4f1c — Spanish invoice lure, SHA-384 fabricated cert, no VS_VERSIONINFO unclassified-nsis-dropper
- 5e1922a744bc unclassified-dotnet-tripledes-resource-loader
- 5a26fd462a80 xloader
- 59cbfe5c — Unclassified JS Dropper
- unclassified-go-pe64: 589af0f8 — Signed Go GUI binary with MD5 hash function, DV cert on maybe.us unclassified-go-pe64
- coinminer (mislabelled): 551d2b0e — PyInstaller ftp-crack sibling, 11 zlib streams, 428 KB overlay coinminer
- unclassified-nsis-dropper: 5212423b — "PI_24000032.exe", 2022-build MSVC 14.29 sibling unclassified-nsis-dropper
- letsdiskusscom: 50a8668b — Update_6.js, 26th sibling, 26th distinct msvcp140.dll morph letsdiskusscom
- Unclassified JS WebDAV Dropper unclassified-js-webdav-dropper
- nfedigitalcom: 4eb1fbf2 — Delphi NFe certificate plugin DLL, May 2026 nfedigitalcom
- 4e286cd9 — Go Reflective Loader (goloader) goloader
- unclassified-dotnet: 4cf48ffc — Spanish RPG character generator, invoice.exe lure unclassified-dotnet
- 4cb05ef0d4a1 unclassified-js-webdav-dropper
- 4c15644f4a1d acrstealer
- unclassified-go-pe64: 4b1d9547 — Go 1.18.5 x64 with 90 randomized main.* functions, unsigned, no static C2 unclassified-go-pe64
- 4818d00fee9f
- xryus-inno-dropper: 45002243 — Microsoft-ID-Verified Inno Setup installer masquerading as EasySuiteer Setup xryus-inno-dropper
- unclassified-js-webdav-dropper: 420bd100 — 60th confirmed sibling, drsyn-prefix batch with rundll32 entry execution unclassified-js-webdav-dropper
- anydesk-batch-dropper: 3f9176f2 — Batch-script AnyDesk stager with SMTP exfil and task-scheduler persistence anydesk-batch-dropper
- esmk-crypter-loader: 3dc65c75 — MinGW-w64 reflective PE loader with nibble-encoded resource payload esmk-crypter-loader
- 3c9f96db10be unclassified-dotnet
- phorpiex sextortion spam bot $800 variant mutex t6 phorpiex
- exeinarchive: 37e8fc3692a6 — javascript-obfuscator JS dropper, Task Scheduler persistence, iteGroup.sbs C2 exeinarchive
- 37d7de1665e2 unclassified-dotnet
- 35eea34350fb unclassified-js-webdav-dropper
- Lumma Stealer: 2f04e1e4 — 17th confirmed sibling, Go 1.25.4 x64, identical .text template to eaa52e19, placeholder cert + five-icon .rsrc + 726 KB null overlay + 2 goroutine closures lummastealer
- Deep Analysis — 2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b avalancherunner
- 9d2ca3 — 2bf8e65c — .NET Framework dropper with AES resource decryption and WMI hollowing 9d2ca3
- unattributed (blackmatter cluster, 18th sibling) unattributed
- 9d2ca3: 29149758 — Go 1.25.4 x64 signed infostealer with randomized module path and fused-string API decoding 9d2ca3
- letsdiskusscom — 26155786a8e0ff9745f18589d31cce9be1f5af922ca0840532b0d1ab0e9db675 letsdiskusscom
- unclassified-batch-powershell-dropper: 2232eb68 — AnyDesk-masquerade .NET batch dropper with PhantomGate loader and IPFS/paste C2 unclassified-batch-powershell-dropper
- connectwise: 2186855f — May 2025 ClickOnce bootstrapper twin, same compile-second as 050e5825 connectwise
- 2120b8b7bf98 lummastealer
- blackmatter (blackmatter cluster): 1985db0655bc — 30th sibling, PE checksum 0x2e30c blackmatter
- Phorpiex sextortion spam bot — MSVCR90 SMTP engine, ZIP constructor, HTTP downloader phorpiex
- Phorpiex sextortion spam bot — MSVCR90 stub with SMTP engine, ZIP constructor, and hardcoded BTC wallet phorpiex
- SilverFox RC4 Loader silverfox
- unattributed: 138b53c5 — Truncated Go PE64+ x64 (30 KB of claimed 2.4 MB image) unattributed
- unattributed: 134a00b7 — Truncated Go PE64+ x64 (262 KB of claimed 2.4 MB image) unattributed
- 1051b5a48a4d unclassified-dotnet-tripledes-resource-loader
- 0de6482c6937 unclassified-js-cjk-stego-dropper
- blackmatter (blackmatter cluster, 27th sibling) blackmatter
- 0bc60a0e1158
- 0b6c65cde50c 54e64e
- 0b6a849a68a4 unclassified-pe32plus
- 0ab9a5703d79
- 0854c21ed764 unclassified-autoit-compiled
- 019d2f45acc4 unclassified-js-webdav-dropper