- unclassified-js-webdav-dropper: 8323305a — 100-entry random-noise dictionary, direct WScript.Shell.run() execution, no PowerShell wrapper 2026-07-23 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — 82d78891aa19 2026-07-23 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 798fa958 — UPX-packed transport of 561c3ff6, 60.06% compression 2026-07-23 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: 77e8e3b2 — 53-variable sequential reassignment, fijnx variant, direct regsvr32 on 193.143.1.231 2026-07-23 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: f51f6323 — 100-entry random-noise dictionary, WebDAV C2 94.159.113.84:8888 2026-07-22 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — f346e80d14c2 2026-07-22 unclassified-js-webdav-dropper
- unclassified-dotnet-bitmap-stego-loader: f31920ba — Eighth confirmed sibling, bank/purchase-order GUI masquerade, mixed PNG+BMP carriers at 256×256/513×513 2026-07-22 unclassified-dotnet-bitmap-stego-loader
- unclassified-js-webdav-dropper: 77aff542 — 91st confirmed sibling, extreme variable-name padding (3,122 chars), rundll32 Entry on 94.159.113.86:8888 2026-07-22 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 561c3ff6 — DHL airway-bill + invoice hybrid lure, 352 KB SCRIPT in .rsrc 2026-07-22 unclassified-autoit-compiled
- Unclassified JS WebDAV Dropper: f2316aaf — Dictionary lookup-table obfuscation (62 entries), new C2 IP 94.159.113.86:8888, rundll32 Entry execution 2026-07-21 unclassified-js-webdav-dropper
- f01dca2e — JavaScript WebDAV Dropper (100-entry dictionary) 2026-07-21 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: edfb0e0a — JScript noise-variable concatenation + sequential reassignment hybrid 2026-07-21 unclassified-js-webdav-dropper
- unclassified-dotnet-tripledes-resource-loader: e8744da8 — ConfuserEx-obfuscated variant with AES-like inner payload 2026-07-21 unclassified-dotnet-tripledes-resource-loader
- unclassified-js-webdav-dropper: e6252c92 — 1.37 MB extreme-padded dictionary JScript, WebDAV C2 94.159.113.79 2026-07-21 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: e2568b43 — 100-entry random-noise JScript dictionary, anti-emulation timeout, WebDAV → regsvr32 2026-07-21 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: e0e66a94 — 52-variable sequential-reassignment JScript variant, 193.143.1.231:8888 2026-07-21 unclassified-js-webdav-dropper
- Vidar (d4b6905ef14c) 2026-07-21 vidar
- unclassified-autoit-compiled: e08d5bcef — RFQ engineering-document lure, 683 KB script in overlay 2026-07-20 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: ddf0c8bd — noise-variable concatenation obfuscation, no dictionary 2026-07-20 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: dca60b6b — DHL airway-bill lure, 493 KB encrypted SCRIPT resource, Dec 2024 build 2026-07-20 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: dbdb99f1 — 2,337-char noise-variable JScript dropper, PowerShell-rundll32 chain 2026-07-19 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: db9d07fd — Invoice-themed AutoItSC v3.3.8.1 with 690 KB encrypted SCRIPT resource (Nov 2024 build) 2026-07-19 unclassified-autoit-compiled
- unclassified-dotnet: db8c072b — DHL-lure dynamic-form generator with embedded RC4-style cipher demo 2026-07-19 unclassified-dotnet
- Unclassified JS WebDAV Dropper — d53e312c — 62-entry noise-key dictionary, new C2 94.159.113.79 2026-07-19 unclassified-js-webdav-dropper
- unclassified-js-german-locale-dropper: d3d22298 — JScript sequential-reassignment HTTP dropper with German LCID sandbox gate 2026-07-19 unclassified-js-german-locale-dropper
- unclassified-nsis-dropper: cbdff40b — inquiry_4387.exe, Deflate-compressed NSIS v3.06.1 with six encrypted payloads 2026-07-19 unclassified-nsis-dropper
- unclassified-js-noise-base64-eval-dropper: c83b7d57 — 1.09 MB noise-padded JScript with sequential variable-reassignment payload extraction 2026-07-19 unclassified-js-noise-base64-eval-dropper
- unclassified-dotnet: c9db49c9 — datalock phone-locker courseware masquerade 2026-07-18 unclassified-dotnet
- unclassified-autoit-compiled: c7eabe28 — LPO procurement lure, 751 KB script in overlay 2026-07-18 unclassified-autoit-compiled
- unclassified-autoit-compiled: c6c17d403f4d — Fifty-first confirmed sibling, Nov 2024 build, procurement-filename lure 2026-07-18 unclassified-autoit-compiled
- c4670e866e87 2026-07-18 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: c3985bb5 — AutoItSC PE32 with 30-byte XOR shellcode decrypting 'myriopodous' inner payload 2026-07-18 unclassified-autoit-compiled
- bf109c1f — Contract_Draft.exe — AutoIt dropper with CallWindowProc shellcode staging 2026-07-18 unattributed
- unclassified-js-webdav-dropper: be448b37 — 75th sibling, sequential reassignment eval, C2 193.143.1.231:8888 2026-07-18 unclassified-js-webdav-dropper
- 127c404a67f2d8c1673bd85759a1875b2e87055c506d769f1b7c699dbefb50bb 2026-07-17 unclassified-autoit-compiled
- unclassified-nsis-dropper: 11a56375 — Tenth confirmed sibling; unsigned BZip2 variant with multi-payload staging 2026-07-17 unclassified-nsis-dropper
- Deep Analysis Report — 0efed3b303e58e99f42f522e0c357c0b42d5999db3770f8bf43513869215c472 2026-07-17 unclassified-autoit-compiled (inner payload: agenttesla)
- unclassified-dotnet: 0e9cc5f81798 — Spanish student-evaluation CRUD app with stolen PuTTY cert masquerading as Adobe Reader 2026-07-17 unclassified-dotnet
- agenttesla: 0ce2a9be — Delphi VCL native stub → raw .NET metadata overlay → AgentTesla infostealer 2026-07-17 agenttesla
- coinminer: 983d2606 — PyInstaller bootloader ninth sibling, Sep 2018 MSVC build, AES-encrypted overlay (2.43 MB) 2026-07-16 coinminer
- unattributed: 89dd9159 — Python 3.13 embeddable runtime dropper with EnumDesktopWindows shellcode callback injection 2026-07-16 unattributed
- Unclassified JS WebDAV Dropper — 0e45e1b2 — JScript 62-entry noise-key dictionary, dailywebstats.com C2 2026-07-16 unclassified-js-webdav-dropper
- 0d3d6bb9 — .NET Framework WinForms checkers/draughts game masquerading as Shipping_docs.exe 2026-07-16 unclassified-dotnet
- unclassified-dotnet: 0bf2e649 — Parcheesi board game + Simple HSM Simulator masquerade 2026-07-16 unclassified-dotnet
- unclassified-dotnet: 0a0a24fc — Polish stock-charting app with stolen Simon Tatham certificate 2026-07-16 unclassified-dotnet
- lummastealer: 040e0d76 — PE32 with .rsrc icons, blizzard-tecnica.com cert, shared type names with d5647efd 2026-07-16 lummastealer
- unclassified-js-webdav-dropper: fe261d49 — 1,794-char extreme variable-name padding dictionary variant 2026-07-15 unclassified-js-webdav-dropper
- fbdd83ad649b 2026-07-15 unclassified-js-webdav-dropper
- chromeloader-pulsar-rat: 94682a96 — .NET stealer/RAT with Pulsar.Common v2.4.5.0, MessagePack C2, and multi-channel exfil 2026-07-15 chromeloader-pulsar-rat
- Unclassified JS WebDAV Dropper — 093a56f6 — JScript 62-entry noise-key dictionary, dailywebstats.com C2 2026-07-15 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper: 00a5ec55 — natural-language SET obfuscation with word-salad padding, 45.9.74.36:8888 2026-07-15 unclassified-js-webdav-dropper
- unclassified-dotnet: 000d931f — Third confirmed Pizzaria POS sibling, purchase-order lure 2026-07-15 unclassified-dotnet
- Unclassified JS WebDAV Dropper: fd437971 — 67th confirmed sibling, sequential variable-reassignment eval obfuscation 2026-07-14 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: fa8c6d74 — noise-variable JScript concat dialect 2026-07-14 unclassified-js-webdav-dropper
- f8dce7df01e6 2026-07-14 unclassified-js-webdav-dropper
- unclassified-dotnet: 495a9aa0 — JapaneseTrainer WinForms app repackaged as draft-file-request lure 2026-07-14 unclassified-dotnet
- unclassified-dotnet: 46c14f54 — OOP inheritance coursework app with purchase-order lure 2026-07-14 unclassified-dotnet
- 438fce55de8d 2026-07-14 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 2d720f57 — Purchase_Order_423737.exe, Charley-branded VS_VERSIONINFO, Sep 2024 build 2026-07-14 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: 4889c168 — 3-line shared-prefix batch, PowerShell wrapper + rundll32 entry 2026-07-13 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 434c5214 — natural-language batch variant, expanded word-salad padding 2026-07-13 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 42c82e1d — 659 KB overlay-script AutoItSC with New_Order.exe procurement lure 2026-07-13 unclassified-autoit-compiled
- 41d04ad59995 2026-07-13 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper 41472c6a — 36-entry noise-key dictionary, no PowerShell wrapper 2026-07-13 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 3f3540e1 — RFQ/ENQUIRY_ORDER tracking-code lure, 381 KB encrypted SCRIPT 2026-07-13 unclassified-autoit-compiled
- 3c63a3c06701 2026-07-13 unclassified-nsis-dropper
- unclassified-autoit-compiled: 3a538ef0 — DHL-document lure, 289 KB SCRIPT resource, Jul 2024 build 2026-07-12 unclassified-autoit-compiled
- unclassified-nsis-dropper: 3a13583c — Product-samples PDF masquerade, stride-6 Danish PowerShell, eight confirmed siblings 2026-07-12 unclassified-nsis-dropper
- Unclassified JS WebDAV Dropper — 385c2f0552de — Fifty-seventh confirmed sibling, 62-entry random-noise dictionary 2026-07-12 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 365235cd — shared-prefix ygfrlo dialect, payload 63.dll 2026-07-12 unclassified-js-webdav-dropper
- formbook: 3424a53f — purchase-order lure with C33JA stride-3 shellcode bootstrap 2026-07-12 formbook
- connectwise: 9477ccddefa6 — Apr 2025 ClickOnce bootstrapper, C2 104.236.198.16:8041 2026-07-11 connectwise
- unclassified-dotnet-crypter-loader: 5f54948e — Transponer masquerade, Unicode name obfuscation, 2.0 MB AES overlay, sixth confirmed sibling 2026-07-11 unclassified-dotnet-crypter-loader
- unclassified-dotnet: 5ea6b79d — Stolen-Tatham-cert pizza POS sibling 2026-07-11 unclassified-dotnet
- unclassified-dotnet: 5e34f10a — Spanish student-evaluation app with PO masquerade 2026-07-11 unclassified-dotnet
- unclassified-js-webdav-dropper: 5e170f1b — natural-language SET batch, WebDAV C2 45.9.74.32:8888, payload 209221036312347.dll, goto basketball 2026-07-11 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 33c0bfaf — 62-entry natural-language dictionary, cloudslimit.com:8888, PowerShell wrapper 2026-07-11 unclassified-js-webdav-dropper
- unclassified-dotnet-chess-engine: 337c323b — Second confirmed sibling, academic-document lure variant 2026-07-11 unclassified-dotnet-chess-engine
- darkcomet: b9b052df — Unpacked Delphi VCL RAT sibling, MSRSAAPP masquerade, identical v5.x command protocol 2026-07-10 darkcomet
- darkcomet: a3fa75fe — UPX-packed Delphi VCL RAT, MSRSAAPP masquerade, v5.x command prefix 2026-07-10 darkcomet
- 5bf25358 — .NET Framework Turkish Monopoly game with purchase-order double-extension masquerade 2026-07-10 unclassified-dotnet
- unclassified-js-webdav-dropper: 5931df0b — 62-entry compound-phrase dictionary, dailywebstats.com:8888 2026-07-10 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 58d9398a — 62-entry noise-key dictionary, dailywebstats.com:8888 2026-07-10 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 5833e797 — 1.11 MB SCRIPT resource, YASREF refinery engineering-document lure 2026-07-10 unclassified-autoit-compiled
- Unclassified AutoIt Compiled PE32 — 54ad2eac 2026-07-10 unclassified-autoit-compiled
- acrstealer: d353d849 — Eighth sibling, module JyUjBKWCTzoLKTp, no static C2 2026-07-09 acrstealer
- connectwise: b831f47e — Third confirmed sibling, C2 at 104.236.198.16:8041 2026-07-09 connectwise
- unclassified-dotnet: 54956960 — Lab4CSharp WinForms picture-viewer lab with CV lure and PictureViewer masquerade 2026-07-09 unclassified-dotnet
- unclassified-dotnet: 5335da6d — WinForms paint editor with Trif32 decoder (QUOTE lure) 2026-07-09 unclassified-dotnet
- unclassified-dotnet: 529fa495 — Karate_Club CRM sibling, .xlsx.exe double-extension masquerade 2026-07-09 unclassified-dotnet
- be44b0c3b1a1 2026-07-08 unclassified-batch-skip4-powershell-dropper
- unclassified-dotnet-bitmap-stego-loader: a497a066 — 21-bitmap maritime-lure sibling, Feb 2020 build 2026-07-08 unclassified-dotnet-bitmap-stego-loader
- unclassified-js-bitbucket-stego-dropper: 56ea37ef — JScript with fixed-delimiter concat obfuscation and image-steganography .NET loader 2026-07-08 unclassified-js-bitbucket-stego-dropper
- Unclassified Batch Self-Extract .NET Dropper: 51500e40 — Shipping-invoice BAT→PowerShell→ConfuserEx .NET chain with byte-reversed gzip payload 2026-07-08 unclassified-batch-selfextract-dotnet-dropper
- unclassified-js-webdav-dropper: 4fdfd354 — 62-entry shared-prefix polyglot, C2 45.9.74.13:8888, payload 515.dll 2026-07-08 unclassified-js-webdav-dropper
- 4f79aee0 — MicroMouseSimul .NET WinForms maze simulator (benign) 2026-07-08 unclassified-dotnet
- unclassified-js-webdav-dropper: 4f20ce5f — random-noise SET batch, WebDAV C2 45.9.74.36:8888, payload 1476539521452.dll 2026-07-08 unclassified-js-webdav-dropper
- unclassified-dotnet-crypter-loader: 4e31a886 — Holyaya masquerade, 473 KB AES overlay, fifth confirmed sibling 2026-07-08 unclassified-dotnet-crypter-loader
- unclassified-autoit-compiled: 4de51fe0 — T30WL8ASV permutation-XOR obfuscation, M31UY3G0 Caesar-1 hex shellcode, camellin/totten dual payload 2026-07-08 unclassified-autoit-compiled
- unclassified-dotnet: 4d780fea — Hadouken WinForms inventory CRUD app with MySQL backend and .bat.exe double-extension lure 2026-07-08 unclassified-dotnet
- unclassified-dotnet-chess-engine: 7d18d78c — Signed WinForMono bitboard chess engine with .pdf.exe double-extension lure 2026-07-07 unclassified-dotnet-chess-engine
- unclassified-autoit-compiled: 7c706df3 — REQUEST_FOR_QUOTATION.exe, July 2024 RFQ lure 2026-07-07 unclassified-autoit-compiled
- unclassified-dotnet: 7b3ef687 — Brazilian pizza-shop POS/CRM, no malicious payload 2026-07-07 unclassified-dotnet
- unclassified-dotnet: 4cce5506 — .NET WinForms checkers game with Security Descriptor Editor masquerade and .pif.exe double-extension lure 2026-07-07 unclassified-dotnet
- unclassified-autoit-compiled: 498f7bf3 — Caesar-3 hex-shellcode with 28-byte XOR key decrypting 229 KB inner PE 2026-07-07 unclassified-autoit-compiled
- unclassified-dotnet: 7a310c85 — KarateClub WinForms CRM repackaged as Purchase_Order.exe 2026-07-06 unclassified-dotnet
- Unclassified JS WebDAV Dropper — 77cbe0c4 — Random-noise dictionary keys, cloudslimit.com@8888, PowerShell -EncodedCommand wrapper 2026-07-06 unclassified-js-webdav-dropper
- unclassified-dotnet: 72d8e3b2 — Stolen-Tatham-cert k-means clustering GUI repackaged as university project lure 2026-07-05 unclassified-dotnet
- unclassified-dotnet: 72c4217f — Croatian-language AES/RSA cryptography coursework tool repackaged as SSLOS2024070909.exe 2026-07-05 unclassified-dotnet
- unclassified-dotnet: 724d94aa — AdvWinProgHW2 calculator with stolen Simon Tatham certificate 2026-07-05 unclassified-dotnet
- 708485983114 2026-07-05 unattributed
- Unclassified JS WebDAV Dropper — Batch Variant 2026-07-05 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 6f72a3a9 — 62-entry compound-phrase dictionary, dailywebstats.com:8888 2026-07-04 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper — 6f1d7c74 — 42nd sibling, polyglot JScript/batch with shared-prefix SET obfuscation 2026-07-04 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: 6d9546a6 — 62-entry three-word compound-phrase dictionary, cloudslimit.com:8888 single-domain C2 2026-07-04 unclassified-js-webdav-dropper
- unclassified-dotnet: 6d114209 — Ivanov_WF_Paint WinForms editor with Trif32 decoder 2026-07-04 unclassified-dotnet
- unclassified-dotnet-protobuf-loader: 6cdc73c8 — Signed .NET RAT with protobuf-net C2, Smadav masquerade 2026-07-04 unclassified-dotnet-protobuf-loader
- unclassified-js-webdav-dropper: 6b7435afd70e — 62-entry noise-key dictionary, dailywebstats.com:8888 2026-07-04 unclassified-js-webdav-dropper
- iobit-driver-booster: a7a9205e — 7-Zip SFX installer for Driver Booster v3.4 2026-07-03 iobit-driver-booster
- unclassified-js-webdav-dropper: 69f29779 — 62-entry compound-phrase dictionary, cloudslimit.com C2 2026-07-03 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 68e48a8c — UPX-packed transport variant of salary-package .com masquerade 2026-07-03 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: 682bea06 — pure batch, natural-language SET obfuscation, 45.9.74.36:8888 2026-07-03 unclassified-js-webdav-dropper
- Deep Analysis — SHA-256 673e673800b807ec8ab291b464f62dc81576874956d702e7cfa152af61844421 2026-07-03 unclassified-dotnet-crypter-loader
- unclassified-autoit-compiled: 6718622d — Final_order.exe, AutoItSC → Caesar-3 hex shellcode → 19-byte XOR → AgentTesla 2026-07-03 unclassified-autoit-compiled
- Unclassified AutoIt Compiled PE32 — thirty-first confirmed sibling 2026-07-03 unclassified-autoit-compiled
- NanoCore RAT — 4121d69c (Backdoor.exe) 2026-07-03 nanocore
- SilverFox AV Teardown Driver-Dropper Variant 2026-07-03
- unclassified-autoit-compiled: 9e95f20b — procurement-BOQ lure with U30JZ3SO7 permutation-XOR obfuscation 2026-07-02 unclassified-autoit-compiled
- unclassified-dotnet: 644892e9 — Spanish RPG character generator masquerading as purchase order (confirmed sibling of ad301389) 2026-07-02 unclassified-dotnet
- unclassified-autoit-compiled: 6395396e — Spanish payment-lure with M30K3JL Caesar-2 obfuscation and 240 KB encrypted payload 2026-07-02 unclassified-autoit-compiled
- unclassified-dotnet: 9a40908c — FSC UI WinForms library second sibling (Zfio build), CV.pdf.exe lure 2026-07-01 unclassified-dotnet
- unclassified-js-webdav-dropper: 976dc607 — thirty-fourth sibling, batch natural-language SET obfuscation with word-salad padding 2026-07-01 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — 94686f16 — Three-word natural-language dictionary variant, cloudslimit.com payload 2026-07-01 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 941a189b — 601 KB overlay-script logistics-tracking lure, VS2010 linker 2026-07-01 unclassified-autoit-compiled
- unclassified-dotnet-crypter-loader: 931242f8 — AMSI-aware AES reflective loader with 2.38 MB encrypted overlay 2026-07-01 unclassified-dotnet-crypter-loader
- unclassified-autoit-compiled: bf0134ff — customer-remittance lure, 249 KB SCRIPT in .rsrc, MSVC 12.0 2026-06-30 unclassified-autoit-compiled
- AgentTesla: bee6e88e — .NET Native AOT-compiled infostealer, Albanian order-confirmation lure 2026-06-30 agenttesla
- unclassified-dotnet: bd60fe2a — RFQ-themed .NET assembly bundling binary-tutorial game + SSH remote-wget tool + JS combiner 2026-06-30 unclassified-dotnet
- unclassified-dotnet-crypter-loader 2026-06-30 unclassified-dotnet-crypter-loader
- unclassified-dotnet: b760c6f2 — .NET WinForms file manager masquerading as purchase-order lure 2026-06-30 unclassified-dotnet
- 92de8242 — GoldenCity .NET WinForms game masquerading as purchase-order PDF 2026-06-30 unclassified-dotnet
- unclassified-dotnet: 8d4d4300 — Node-graph WinForms editor, no payload 2026-06-30 unclassified-dotnet
- Unclassified JS WebDAV Dropper 2026-06-29 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: b612dd70 — 36-entry noise-key dictionary variant, 45.9.74.36:8888 C2 2026-06-29 unclassified-js-webdav-dropper
- unclassified-dotnet: b4814a17 — VD_Pacman + CalculatorWinForms dual-namespace masquerade, stolen Simon Tatham cert 2026-06-29 unclassified-dotnet
- unclassified-js-webdav-dropper: b32ea531 — Twenty-eighth sibling, natural-language SET batch, 45.9.74.36:8888 2026-06-29 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — Natural-Language SET Sibling 2026-06-29 unclassified-js-webdav-dropper
- Analysis Report — b0c43e946344c90398d20293a6e3356e9f922a6dcbe2b5134225cc94cf342412 2026-06-29 unclassified-js-rentry-telegram-dropper
- b094a2b61576 2026-06-29 unclassified-dotnet
- brooter: b04aa5d0 — Russian Delphi VCL brute-forcer with ICQ contact, SALES_INQUIRY.pdf.exe lure 2026-06-28 brooter
- b01c9133 — FREIGHT_INVOICE_80189CD_PDF.js 2026-06-28 unclassified-js-horus-dropper
- unclassified-autoit-compiled: b017d189 — AutoItSC shellcode→.NET infostealer, K30ZWMBJJ string obfuscation 2026-06-28 unclassified-autoit-compiled
- unclassified-dotnet: ad301389 — Spanish RPG character generator masquerading as purchase order 2026-06-28 unclassified-dotnet
- unclassified-js-webdav-dropper: aac0198b5 — 62-entry natural-language dictionary, cloudslimit.com:8888, PowerShell wrapper 2026-06-28 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper: aa8ff8b9 — 36-entry noise-key dictionary obfuscation, C2 45.9.74.36:8888 2026-06-27 unclassified-js-webdav-dropper
- Deep-dive — a9b5e7469c35f0cd7da326f9894d002a8bbe77377a11bbc03551dcbadab3b47a 2026-06-27 unclassified-dotnet
- Deep Analysis — a8beee89eb72 2026-06-27 unclassified-autoit-compiled
- formbook: a4cb4c76 — AutoIt dropper with PFMD87JH468RAUYH XOR key and shellcode bootstrap 2026-06-27 formbook
- unclassified-dotnet: a42443c8 — PrimeraVentana Spanish educational app repackaged as University-of-Bahrain project 2026-06-27 unclassified-dotnet
- unclassified-autoit-compiled: 891df280 — salary-package .com masquerade, 552 KB encrypted SCRIPT resource 2026-06-27 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: e11665cf — natural-language word-salad SET obfuscation, WebDAV C2 45.9.74.36:8888 2026-06-26 unclassified-js-webdav-dropper
- unclassified-dotnet: e04d46ff — FSC UI WinForms library with embedded SHA256 integrity hash, social-engineering filename 2026-06-26 unclassified-dotnet
- Unclassified JS WebDAV Dropper: df42ecf8 — Twentieth sibling, 62-entry noise-key dictionary on cloudslimit.com 2026-06-26 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: ded287fe — Bangladesh IT-park lure with 805 KB encrypted SCRIPT resource 2026-06-26 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: dc9b0407 — 19th sibling, shared-prefix batch SET obfuscation, rundll32 entry 2026-06-26 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: a435a37b — 36-entry noise-key dictionary variant, 45.9.74.36:8888 C2 2026-06-26 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: a3419c27a — 62-entry natural-language dictionary, cloudslimit.com:8888 2026-06-26 unclassified-js-webdav-dropper
- unclassified-dotnet: a1e6dc7a — Fourth stolen-Tatham-cert sibling, WinForms paint app masquerading as Adobe Reader 2026-06-26 unclassified-dotnet
- Unclassified JS WebDAV Dropper: dac5e0ee — 18th Confirmed Sibling 2026-06-25 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: d86e0912 — UPX-packed AUG_SOA.exe, 802 KB compiled AutoIt script in .rsrc 2026-06-25 unclassified-autoit-compiled
- unclassified-dotnet-bitmap-stego-loader: d4d106f8 — Sixth confirmed sibling, .text-section bitmap embedding, event-registration GUI masquerade 2026-06-25 unclassified-dotnet-bitmap-stego-loader
- Unclassified JS WebDAV Dropper: d36d84f2 — Seventeenth Confirmed Sibling 2026-06-25 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper: d1af0ff50c793f0f941bd1c38511dc87c050d42185f54ffac5861a31c7d2e20d 2026-06-25 unclassified-js-webdav-dropper
- unclassified-js-webdav-dropper: d0124d62 — 36-entry dictionary JS, WebDAV C2 45.9.74.36:8888, payload 1783941328258.dll 2026-06-24 unclassified-js-webdav-dropper
- unclassified-nsis-dropper: cf9a061d — PDF-masquerade NSIS v3.02 with stride-8 Danish PowerShell + two encrypted PE payloads 2026-06-24 unclassified-nsis-dropper
- Unclassified JS WebDAV Dropper — cc90d6c — Alliterative dictionary obfuscation, dailywebstats.com C2 2026-06-24 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — Shared-Prefix SET Variant (Tenth Sibling) 2026-06-23 unclassified-js-webdav-dropper
- unclassified-js-s3-dropper: 2dbebbafe9d9 — XOR-obfuscated WScript→S3 HTTPS downloader sibling 2026-06-23 unclassified-js-s3-dropper
- Unclassified JS WebDAV Dropper: fb353965 — Ninth sibling, dual-domain C2 cloudslimit/cloudskimit 2026-06-22 unclassified-js-webdav-dropper
- unclassified-dotnet: c62e2921 — .NET PE32 with embedded NModbus library, TripleDES crypto, and reflective assembly loading 2026-06-22 unclassified-dotnet
- unclassified-dotnet-minesweeper-masquerade: c59a535b — .NET Framework Minesweeper game with Microsoft-themed version-info masquerade 2026-06-22 unclassified-dotnet-minesweeper-masquerade
- unclassified-dotnet: c4ee3a31081d — Spanish WinForms educational app repackaged with stolen Simon Tatham cert and HAWB logistics lure 2026-06-22 unclassified-dotnet
- Unclassified AutoIt Compiled PE32 — UPX-packed Invoice.exe variant 2026-06-21 unclassified-autoit-compiled
- unclassified-js-webdav-dropper — fa7e181d — dictionary-lookup JS dropper, shared C2 45.9.74.36:8888 2026-06-21 unclassified-js-webdav-dropper
- unclassified-rust-dropper-2024: f97c10fc — Industrial RFQ lure, tokio+reqwest payload fetch, NtWriteVirtualMemory injection 2026-06-21 unclassified-rust-dropper-2024
- unclassified-nsis-dropper: f7f089f7 — Danish-character-skip PowerShell + four encrypted PE payload NSIS SFX 2026-06-21 unclassified-nsis-dropper
- unclassified-dotnet: f7c4caea — ReichUI WinForms library repackaged as purchase-order lure 2026-06-21 unclassified-dotnet
- unclassified-autoit-compiled: f527ce01 — 1012024.exe, 413 KB SCRIPT, numeric-date lure 2026-06-20 unclassified-autoit-compiled
- unclassified-autoit-compiled: f51bc678 — FDA.exe, 196 KB SCRIPT, PDF-icon masquerade 2026-06-20 unclassified-autoit-compiled
- unclassified-dotnet-transmock-masquerade: f3bc22f6 — .NET PE masquerading as TransMock utility with WinHTTP downloader and encrypted payload staging 2026-06-20 unclassified-dotnet-transmock-masquerade
- Unclassified AutoIt Compiled PE32: f3a48a8c — PO lure, 313 KB encrypted script, PCRE runtime 2026-06-20 unclassified-autoit-compiled
- unclassified-autoit-compiled: f346b7e9 — 659 KB overlay-script PO lure, Jan 2012 AutoItSC v3.3.8.1 2026-06-20 unclassified-autoit-compiled
- unclassified-autoit-compiled: f2be9e06 — PO_#86637.exe, 417 KB SCRIPT, PCRE regex library 2026-06-19 unclassified-autoit-compiled
- unclassified-dotnet-bitmap-stego-loader: f230118d — engineering PO lure with AES+Deflate bitmap payload chain 2026-06-19 unclassified-dotnet-bitmap-stego-loader
- Unclassified AutoIt Compiled PE32: f0059bee — 932 KB SCRIPT resource, procurement lure 2026-06-19 unclassified-autoit-compiled
- unclassified-autoit-compiled: ef71e0f6 — AutoItSC PE32 with 186 KB encrypted SCRIPT resource, 'Public Holiday Notice' payroll lure 2026-06-19 unclassified-autoit-compiled
- unclassified-dotnet: eea0dcbc — Stolen-cert attendance tracker masquerading as payment document 2026-06-19 unclassified-dotnet
- unclassified-js-webdav-dropper: ed6b2cd3 — Sixth confirmed sibling, labzf-prefix SET obfuscation, rundll32 entry execution 2026-06-19 unclassified-js-webdav-dropper
- unclassified-batch-string-slice-dropper: eae731d3 — FTSP.zip Python stager, UTF-16 LE variant with corrected %USERPROFILE% expansion 2026-06-19 unclassified-batch-string-slice-dropper
- petpack: ea56cf43d33b — AES-managed .NET loader, Serbian banking lure, timestamped Aug 2024 2026-06-18 petpack-dotnet
- unclassified-dotnet: e7aaacbb — .NET Framework educational crypto lab repackaged as DHL shipping lure 2026-06-18 unclassified-dotnet
- Unclassified JS WebDAV Dropper — Shared-Prefix SET Variant 2026-06-18 unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper — e6ebae6a — JScript dictionary obfuscation + WebDAV regsvr32 chain 2026-06-18 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: 6cc26f7c — UPX-packed AutoItSC shipping-lure, 241 KB SCRIPT in .rsrc 2026-06-18 unclassified-autoit-compiled
- unclassified-autoit-compiled: 1d0834e7 — Greek invoice-lure, 221 KB SCRIPT, plain AutoItSC 2026-06-18 unclassified-autoit-compiled
- Unclassified JS WebDAV Dropper — Batch Variant 2026-06-17 unclassified-js-webdav-dropper
- unclassified-autoit-compiled: ff84806a — Jan 2012 AutoItSC v3.3.8.1, script-in-overlay variant 2026-06-17 unclassified-autoit-compiled
- unclassified-batch-string-slice-dropper: aa443a5285 — FTSP.zip Python stager with 64-char string-slice obfuscation 2026-06-17 unclassified-batch-string-slice-dropper
- unclassified-go-pe64: 9665ccc9 — Go 1.25.1 PE64+ with fake WindowsSoundDiagnostics source-path masquerade 2026-06-17 unclassified-go-pe64
- Unclassified AutoIt Compiled PE32 — Invoice.exe sibling 2026-06-17 unclassified-autoit-compiled
- remusstealer: 2b2293a0 — Protector Lab (plab) AES-GCM overlay packer, May 2026 MinGW-w64 x64 2026-06-17 remusstealer
- avalancherunner: f7352bc1 — Third confirmed sibling, bomb-defusal skin, PDF-masquerade version info, no encrypted CLR payload 2026-06-16 avalancherunner
- Deep Analysis — f6b5bdd5958eefc7f7e595ee8e91c2407193226acad0bfa939f3a1a42cf08396 2026-06-16 unclassified-dotnet-bitmap-stego-loader
- unclassified-pe64-clipper: af6e1f46 — MinGW-w64 infostealer with wallet regex, Telegram user ID, and screenshot capture 2026-06-16 unclassified-pe64-clipper
- unclassified-autoit-compiled: ac2ca060 — AutoItSC PE32 with 802 KB encrypted SCRIPT resource, 'AUG_SOA' business lure 2026-06-16 unclassified-autoit-compiled
- test: 7a2c8630 — MalwareBazaar test-upload ZIP with trivial Python payload 2026-06-16 test
- remcos — v1.7 Pro, Jan 2017 — 803-byte SETTINGS RCData variant 2026-06-16 remcos
- 341165a42115 2026-06-16 hippamsascom
- unclassified-js-s3-dropper: 26afa8d1 — Plain-text WScript→S3 HTTPS downloader with SSL cert-error bypass 2026-06-16 unclassified-js-s3-dropper
- coinminer: 058ab625 — PyInstaller bootloader eighth sibling, Sep 2018 MSVC build, AES-encrypted overlay (2.76 MB) 2026-06-16 coinminer
- uniqfile: e79a525e — MinGW-w64 x86 .rdata payload with XOR-loop reflective loader 2026-06-15 uniqfile
- asyncrat: e57d8c5a — VIN88APP.exe sibling, ~28 KB builder-default stripped build 2026-06-15 asyncrat
- hippamsascom: c20bbb80 — Olson Group masquerade, 502 semantic export flood, self-loading dropper 2026-06-15 hippamsascom
- poabu-inno-dropper: bb3fd6cd — Authenticode-signed Inno Setup 6.7.0 masquerading as contact-indexing service 2026-06-15 poabu-inno-dropper
- wannacry: ad4df92f — WannaCry v2.0 sibling, kill-switch wea.com, service name 2.0 2026-06-15 wannacry
- 8eddf076bf8b 2026-06-15 hippamsascom
- asgardprotector: 87a158f2 — Signed IExpress SFX dropper with stolen FileZilla cert, AutoIt3 + Easter.a3x 2026-06-15 asgardprotector
- connectwise: 7145e8 — Self-contained MSI-based ScreenConnect client installer, hardcoded C2 at 134.122.4.2:8041 2026-06-15 connectwise
- Phorpiex x64 CPlApplet PNG Payload Dropper 2026-06-15 phorpiex
- asyncrat: 2b125840 — Google Chrome masquerade, builder-default MessagePack C2 client 2026-06-15 asyncrat
- 177bfc846a77 2026-06-15 netsupport-inno-dropper
- Phorpiex Downloader Sibling — 13/14/peinf/xmr/xmrget Chain, Earliest Build 2026-06-14 phorpiex
- gh0st: e65bbcad — Qt6 x64 RAT with encrypted payload blob, March 2026 2026-06-14 gh0st
- Unclassified JS WebDAV Dropper 2026-06-14 unclassified-js-webdav-dropper
- xenorat: c50bb7b4 — au88-branded v0.0.2.0 sibling with LZNT1 async C2 2026-06-14 xenorat
- unclassified-danish-batch-ps-dropper: 402879ff4b36 — Character-skip BAT→PowerShell downloader, Italian C2 2026-06-14 unclassified-danish-batch-ps-dropper
- 028301d695ca 2026-06-14 unclassified-python-ngrok-rat
- d0ca14b3ad12 2026-06-13 letsdiskusscom
- 9dc2cded28a0 2026-06-13 letsdiskusscom
- 54e64e: 7aed04ab — Signed IExpress SFX with AutoIt3 payload + batch variable-expansion reconstruction 2026-06-13 54e64e
- 54e64e: 6e0ef3af — MSVC x64 XMM-loader with 2.8 MB encrypted .data payload 2026-06-13 54e64e
- Remcos RAT: 6114904c — v1.7 Pro sibling, 616-byte SETTINGS RCData, no version info 2026-06-13 remcos
- 247b54b524dc 2026-06-13 letsdiskusscom
- 404356dbc85c — ALL SHIPPING DOC DRAFT BL.JS 2026-06-12 unclassified-js-dropper
- Vidar (3799d1f74d95) 2026-06-12 vidar
- coinminer: fbfd2d94 — 2.37 MB PyInstaller sibling, Sep 2018 cluster, 89% zlib overlay 2026-06-11 coinminer
- unclassified-dotnet-bitmap-stego-loader: f74d8a51 — 984 KB fleet-maintenance masquerade with SOAP/HTTP reference 2026-06-11 unclassified-dotnet-bitmap-stego-loader
- Unclassified .NET Bitmap-Stego Loader: db0d6bc0 — Purchase Order.exe, May 2022 build 2026-06-11 unclassified-dotnet-bitmap-stego-loader
- nanocore: d065ebea — VB.NET ConfuserEx sibling, NanoCore v1.2.2.0 RAT (hotro.exe) 2026-06-11 nanocore
- 54e64e: 8017acd5 — Go 1.25.4 signed PE64+ with fabricated godaddy.com/WE1 Authenticode 2026-06-11 54e64e
- nanocore: 48c8e8a2 — VB.NET ConfuserEx sibling, NanoCore v1.2.2.0 RAT 2026-06-11 nanocore
- phorpiex: 32f29422 — Earliest-build thin MSVC9 downloader sibling (4-payload chain, grab.exe fallback) 2026-06-11 phorpiex
- silentnet: dbe586b5 — Zig 0.12.0 PE64 launcher with XOR-obfuscated C2 and TLS 1.3 HTTP client 2026-06-10 silentnet
- gerador-loader: 55db7544 — Brazilian MSVC loader stub, Defender exclusion + HTTP cradle 2026-06-10 gerador-loader
- 4978e16a7f6b 2026-06-10 unclassified-nsis-dropper
- Phorpiex Downloader Sibling — peinf/xmr/xmrget Chain 2026-06-10 phorpiex
- overwolf-teamspeak-helper: 2d2a251a — Signed MSVC C++ PE32+ x64, benign application mis-tagged in MalwareBazaar 2026-06-10 overwolf-teamspeak-helper
- silverfox: 17d6415d — DLL side-loader masquerading as MaxxAudioAPOShell64 with anti-VM gates 2026-06-10
- wannacry: 16fdcfbc — May 2017 outbreak DLL, kill-switch + EternalBlue + 27-language ransom note ZIP 2026-06-10 wannacry
- unclassified-dotnet-crypter-loader: 07835853 — .NET Framework 4.0 reflective loader with AES-GZip-Base64 manifest-resource decryption and native API P/Invoke 2026-06-10 unclassified-dotnet-crypter-loader
- unclassified-pe32-clipper: f936b99e — MSVC C++ Telegram-relayed crypto clipper with registry persistence 2026-06-09 unclassified-pe32-clipper
- acrstealer: d5655568 — Fourth signed Go 1.26.2 sibling, module JPYhJIzovpOdAaG, custom PE parser + multi-pass decoder 2026-06-09 acrstealer
- d52f85: 2fb095b1 — CS2 external cheat 'Cheetah' dropped by Amadey 2026-06-09 d52f85
- avalancherunner: 1a38a948 — Uzbek-languaged .NET game-masquerade loader with encrypted CLR resource payload 2026-06-09 avalancherunner
- zenconnekt: cd97c264 — Go PE64+ modular RAT, signed, C2 over TLS+WebSocket, Microsoft masquerade 2026-06-08 zenconnekt
- coinminer: b4cc27e3 — Smallest PyInstaller bootloader sibling, 630 KB, Python 2.7 payload 2026-06-08 coinminer
- 9d2ca3 Go Cluster: 389e1ccf — EclipseV2.exe, x64 sibling with GoDaddy-masquerade cert 2026-06-08 9d2ca3
- phorpiex: bb77ef06 — $500 USD sextortion spam bot, earliest known May-22 campaign build 2026-06-07 phorpiex
- unclassified-go-pe64: 82ee3cdd — Go 1.25.4 signed PE64 with multi-pass payload decryption and in-memory PE loader 2026-06-07 unclassified-go-pe64
- connectwise: 81adbf9a — Authenticode-backed ClickOnce runner for ScreenConnect remote-access deployment 2026-06-07 connectwise
- quasar 2026-06-07 quasar
- phorpiex: 025f5798 — MSVC9 thin HTTP downloader, earlier build (13:06 UTC) missing 15.exe payload 2026-06-07 phorpiex
- unclassified-pe32-nfe-loader: ded59ec4 — MinGW AES-like dropper, Brazilian NFe lure 2026-06-06 unclassified-pe32-nfe-loader
- unclassified-pe32-nfe-loader: ac20be18 — 4 KB MinGW launcher stub for core.dll 2026-06-06 unclassified-pe32-nfe-loader
- xenorat: 6133cd0b — .NET Framework 4.8 RAT, LZNT1 compression, async C2 node architecture 2026-06-06 xenorat
- coinminer: 359fcf01 — PyInstaller bootloader sibling, Sep 2018 MSVC build, AES-encrypted overlay with weak QWERTY key 2026-06-06 coinminer
- hippamsascom: 1cf56da3 — Mayer-Ondricka CSS matrix self-loading dropper 2026-06-06 hippamsascom
- quasar 2026-06-06 quasar
- remcos: c6193af6 — v1.7 Pro, enlarged 593-byte SETTINGS RCData 2026-06-05 remcos
- 4bf14434ef61 2026-06-05 unclassified-dotnet-bitmap-stego-loader
- silverfox: e772de93 — C x64 stub with Sangfor EDR masquerade and dual-lang .rsrc icon set 2026-06-04 silverfox
- remcos: 5a1e57f7b0 — v1.7 Pro sibling, 531-byte SETTINGS RCData 2026-06-04 remcos
- silverfox: 452e085f — MSVC C++ x64 process hollowing injector with LZSS decompressor and privilege escalation 2026-06-04 silverfox
- 027aeb2eb483 2026-06-04 unclassified-pe32
- cae0056acc2f 2026-06-03 unclassified-batch-powershell-dropper
- phorpiex: 6b8527a7 — MSVC9 thin HTTP downloader with mutex-gated payload branching 2026-06-03 phorpiex
- remcos: 0f723826 — v1.7 Pro, Jan 2017, no packer 2026-06-03 remcos
- nanocore: fe81691f — VB.NET ConfuserEx dropper, NanoCore v1.2.2.0 RAT 2026-06-02 nanocore
- 54e64e: c8db13c1 — UPX-packed x64 sibling with modified packer, zero readable strings, Amadey-dropper pedigree 2026-06-02 54e64e
- 9d2ca3: a7b9f3dd — Go 1.25.4 PE64 infostealer with randomized module path and fabricated Authenticode 2026-06-02 9d2ca3
- coinminer: 640ed5b5 — PyInstaller bootloader sibling, 735 KB, September 2018 cluster 2026-06-02 coinminer
- coinminer: 5047235c — PyInstaller bootloader sibling with appended sub-PE, 1.8 MB overlay 2026-06-02 coinminer
- unclassified-js-dropper: 0e4141aa — WScript→PowerShell→.NET assembly loader with debugger/sandbox gate 2026-06-02 unclassified-js-dropper
- maskgramstealer: abeaa63b — MinGW-w64 PE64 infostealer with runtime API resolution and wallet-seed regex 2026-06-01 maskgramstealer
- 54e64e: 3b13b28c — MSVC C++ certpert dropper with fake diagnostic masquerade, Defender exclusion, and HTTP payload fetch 2026-06-01 54e64e
- 9d2ca3: 2d39ed5e — Amadey-dropper, MinGW-w64 x64 with 2.55 MB encrypted .data payload 2026-06-01 9d2ca3
- lummastealer: e03dd36f — x64 sibling, fraudulent cert, runtime API decoding 2026-05-31 lummastealer
- ayrseushop: 5a5b3373 — MSVC x64 infostealer with runtime string-decryption, clipboard+screenshot harvesting 2026-05-31 ayrseushop
- 0c9e772d8730 2026-05-31 hippamsascom
- pyinstaller-pyarmor-dropper: d297973f — PyInstaller single-file bootloader with PyArmor-obfuscated Python 3.13 payload 2026-05-30 pyinstaller-pyarmor-dropper
- dolphin: ca6be0bf — Rust x64 polymorphic RAT/stealer with 80+ task types, WebSocket C2, masquerading as NVIDIA Display Container LS 2026-05-30 dolphin
- silverfox: 82d42551 — Lean C-based x64 stub (50K) sharing stream-cipher constants and thunk dispatch 2026-05-30 silverfox
- menomoushop: 3aca18df — Go 1.25.4 PE64 infostealer, Authenticode signed CN=maybe.us, randomized function names 2026-05-30 menomoushop
- 129ef9250b91 2026-05-30 spamita
- euone: 0c9236cf — Delphi VCL installer with embedded 202 KB RCData payload 2026-05-30 euone
- acrstealer: f93d8d79 — Signed Go 1.26.2 sibling with stripped .rsrc, module gesiimdPYMojqEh 2026-05-29 acrstealer
- silverfox: ed1a0047 — Rust x64 dropper with LZSS payload extraction and ntdll unhooking 2026-05-29 silverfox
- prometei: e6ce5dd2d422 — UPX-packed ELF64 systemd dropper, HTTP CGI C2 2026-05-29 prometei
- lummastealer: d5647efd — Go 1.25.4 signed PE32, no .rsrc, certificate www.sjabr.org 2026-05-29 lummastealer
- neuralpulsecore5sbs: 47a2204d — First x64 sibling, Sectigo-signed, no hardcoded C2 2026-05-29 neuralpulsecore5sbs
- Deep Analysis: 1bfebf79c24d0813eb39fec74637d52b008188812631a4f666a59fae7c0cef2c 2026-05-29 acrstealer
- acrstealer: 16a4344d — Signed Go 1.26.2 PE32, module hlHtIOAoWQhvCrI, cert CN=me.muz.li 2026-05-29 acrstealer
- asgardprotector: d59dc2f2 — IExpress SFX dropper embedding AutoIt3 + compiled A3X script 2026-05-27 asgardprotector
- asgardprotector: d364a2f6 — IExpress SFX dropper embedding AutoIt3 + Dayton.a3x script 2026-05-27 asgardprotector
- acrstealer: c577c6c8 — Signed Go 1.26.2 PE32 sibling, randomized module PfeYrYvazVUGgZq 2026-05-27 acrstealer
- coinminer: c4ac7426 — Signed 7-Zip SFX dropper, VC++ redist masquerade, password-protected archive 2026-05-26 coinminer
- coinminer: 801fbba1 — PyInstaller bootloader, Sep 2018 MSVC build, embedded Python payload 2026-05-26 coinminer
- unclassified-js-webdav-dropper: 771c8752 — 90th confirmed sibling, hybrid reassignment+concatenation dialect, davww7root typo 2026-05-26 unclassified-js-webdav-dropper
- acrstealer: 6871848b — Signed Go 1.26.2 PE32, randomized module names, C2 5.252.155.72 2026-05-26 acrstealer
- meterpreter: 5da21aa2 — x64 reverse_tcp stager with inline sockaddr, zero IAT 2026-05-26 meterpreter
- 563db9705ede 2026-05-26 unclassified-js-webdav-dropper
- coinminer: 39b67a79 — PyInstaller bootloader sibling, 4.3 MB with 94% zlib overlay 2026-05-26 coinminer
- chacha8: svchost.exe — ChaCha20 stream-cipher file encryptor with in-place overwrite, no C2 2026-05-26 chacha8
- nfedigitalcom - ffdd7105 nfedigitalcom
- Unclassified JS WebDAV Dropper — Sibling 68 unclassified-js-webdav-dropper
- fbc07658954f valleyrat
- fb5bc5438cc0 unclassified-autoit-compiled
- sunwukong — fa16b64a — Semantic export obfuscation and PEB-walking API resolution sunwukong
- Deep-Dive Report — f9a1fc01119ed1cc7a5464cc4df2d3f0dea09f8227c6ba101c77c73f6c379214 unclassified-dotnet
- f618a8619ab4 unclassified-autoit-compiled
- unclassified-js-webdav-dropper: f170f5a9 — Seventh sibling, natural-language SET obfuscation, WebDAV C2 45.9.74.36:8888 unclassified-js-webdav-dropper
- ef48ae9e7d02 unclassified-dotnet-native-aot-loader
- unclassified-batch-powershell-dropper: eda47a53 — pastefy/GitLab variant, Sostsenrer2 C2 unclassified-batch-powershell-dropper
- ebceb9dbc06f mirai
- e9e82d14538b unclassified-js-webdav-dropper
- unclassified-destructive-batch: e844c4cb — 982-byte batch script masquerading as a DDoS tool that destroys system32 unclassified-destructive-batch
- unclassified-dotnet: e816172f — TimeToRun C# snippet compiler, benign developer tool unclassified-dotnet
- unclassified-autoit-compiled: e5647a2d — 1.36 MB invoice-lure with 710 KB encrypted script in overlay unclassified-autoit-compiled
- unclassified-js-webdav-dropper unclassified-js-webdav-dropper
- Unclassified JS WebDAV Dropper: dc76a67d — 1,255-char variable noise-key dictionary unclassified-js-webdav-dropper
- d9c0bc24413e unclassified-dotnet-whisper
- d990bd1b64d3 unclassified-autoit-compiled
- d90baa30d713 unclassified-js-webdav-dropper
- d5b11a1cb3ad unclassified-pe32-dotnet
- eu0file: d46e2b49 — False positive: legitimate Windows 8.1 mspaint.exe mis-tagged in gcleaner distribution context eu0file
- d3bb6eb48a3f asyncrat
- ceacabb454c2 unclassified-js-webdav-dropper
- ce07d963d3c5 unclassified-dotnet-strong-masquerade
- unclassified-js-webdav-dropper ccb2d007 — Thirteenth sibling unclassified-js-webdav-dropper
- cca7d56dffd8 unclassified-autoit-compiled
- 54e64e (misattributed): cc4aa789 — Go 1.25.4 x64 signed infostealer, randomized main functions, no hardcoded C2 54e64e
- cbadab4db7d5
- cb5d302f6577 unclassified-js-webdav-dropper
- unclassified-dotnet: cae7ac1dc419 — PrimeraVentana Spanish educational app repackaged with stolen Simon Tatham (PuTTY) Authenticode certificate unclassified-dotnet
- c9c81f5be1bd unclassified-autoit-compiled
- unclassified-autoit-compiled: c80ef443 — UPX-packed RFQ lure, 220 KB SCRIPT resource unclassified-autoit-compiled
- unclassified-autoit-compiled: c310cb2e — UPX-packed duplicate of e5647a2d invoice-lure unclassified-autoit-compiled
- silverfox: beb3a9d9 — Authenticode-signed C x64 sibling with LZSS .rdata payload and process enumeration silverfox
- unclassified-js-webdav-dropper: be58d381 — Thirty-first confirmed sibling, 36-entry noise-key dictionary, WebDAV C2 45.9.74.36:8888 unclassified-js-webdav-dropper
- be172014 — JScript WebDAV Dropper with Dictionary-Lookup Obfuscation unclassified-js-dropper
- unclassified-nsis-dropper: b3fb616d — "Revised_PI_2024.exe", stride-6 Danish character-skip PowerShell unclassified-nsis-dropper
- unclassified-js-webdav-dropper: ade6cf68 — 36-entry noise-key dictionary, WebDAV C2 45.9.74.36:8888, payload 3118252697895.dll unclassified-js-webdav-dropper
- accd2ccd2be4
- abf498a10e71 asyncrat
- aa4d237c7a9b
- a94a77a31e66
- unclassified-js-pptx-dropper: a8c581f2 — javascript-obfuscator RC4 dropper fetching PowerShell from bare IP unclassified-js-pptx-dropper
- unclassified-go-pe64: a5520aba — Go PE64+ signed with GoDaddy DV cert, MD5/SHA256 crypto routines, zero static C2 unclassified-go-pe64
- AsyncRAT: a41d0d35 — System Informer masquerade, stripped build (no keylogger, no plugins) asyncrat
- Unclassified JS WebDAV Dropper unclassified-js-webdav-dropper
- a1943a9a0da7 uniqfile
- unclassified-nsis-dropper: 9c43b920 — "Documents.exe", NSIS v3.02 with six-file embedded payload unclassified-nsis-dropper
- Unclassified JS WebDAV Dropper unclassified-js-webdav-dropper
- 9a3c18be3957 hippamsascom
- 99e5d5d8e7e0 unclassified-dotnet-inventory-app
- 9829594064f4
- 92ce4217922a unclassified-js-webdav-dropper
- Unclassified AutoIt Compiled PE32: 7bfa4723 — Purchase-order lure, 768 KB encrypted script in overlay unclassified-autoit-compiled
- unclassified-nsis-dropper: 78c5e8ca — "Ref_7021929821US20240709031221650.exe", stride-6 Danish character-skip PowerShell unclassified-nsis-dropper
- 7768873f4b7e unclassified-autoit-compiled
- unattributed: 771c7952 — .NET Framework semantic-name masquerade loader, HttpClient+GZip reflective assembly unattributed
- 763ae850f760 unclassified-autoit-compiled
- Phorpiex spam dropper — screensaver-masqueraded MSVCR90 stub with .rsrc payload staging phorpiex
- unattributed: 73d7c8e5 — Delphi VCL purchase-order masquerade, no observable payload unattributed
- 7317e559dedf unclassified-autoit-compiled
- 710f15302859 remotepe
- orderreshop: 6f6f0525 — Go infostealer with custom PE parser and multi-pass string decoder orderreshop
- 6e5e5715059b unclassified-js-webdav-dropper
- 6bc4e16d2dee unclassified-dotnet
- 6b33d2019626 remotepe
- unclassified-dotnet: 6a53c56172ce — PrimeraVentana Spanish educational app repackaged with LUA Client masquerade unclassified-dotnet
- 630202e68560 hippamsascom
- 62e040a32aac remotepe
- 624f52cc31cd acrstealer
- 61c1041120dd unclassified-dotnet
- 5e1922a744bc unclassified-dotnet-tripledes-resource-loader
- 59cbfe5c — Unclassified JS Dropper
- unclassified-go-pe64: 589af0f8 — Signed Go GUI binary with MD5 hash function, DV cert on maybe.us unclassified-go-pe64
- unclassified-nsis-dropper: 5212423b — "PI_24000032.exe", 2022-build MSVC 14.29 sibling unclassified-nsis-dropper
- Unclassified JS WebDAV Dropper unclassified-js-webdav-dropper
- nfedigitalcom: 4eb1fbf2 — Delphi NFe certificate plugin DLL, May 2026 nfedigitalcom
- 4e286cd9 — Go Reflective Loader (goloader) goloader
- unclassified-dotnet: 4cf48ffc — Spanish RPG character generator, invoice.exe lure unclassified-dotnet
- 4cb05ef0d4a1 unclassified-js-webdav-dropper
- 4818d00fee9f
- unclassified-js-webdav-dropper: 420bd100 — 60th confirmed sibling, drsyn-prefix batch with rundll32 entry execution unclassified-js-webdav-dropper
- anydesk-batch-dropper: 3f9176f2 — Batch-script AnyDesk stager with SMTP exfil and task-scheduler persistence anydesk-batch-dropper
- esmk-crypter-loader: 3dc65c75 — MinGW-w64 reflective PE loader with nibble-encoded resource payload esmk-crypter-loader
- 3c9f96db10be unclassified-dotnet
- 37d7de1665e2 unclassified-dotnet
- 35eea34350fb unclassified-js-webdav-dropper
- Deep Analysis — 2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b avalancherunner
- 9d2ca3 — 2bf8e65c — .NET Framework dropper with AES resource decryption and WMI hollowing 9d2ca3
- 9d2ca3: 29149758 — Go 1.25.4 x64 signed infostealer with randomized module path and fused-string API decoding 9d2ca3
- Phorpiex sextortion spam bot — MSVCR90 SMTP engine, ZIP constructor, HTTP downloader phorpiex
- Phorpiex sextortion spam bot — MSVCR90 stub with SMTP engine, ZIP constructor, and hardcoded BTC wallet phorpiex
- SilverFox RC4 Loader silverfox
- 1051b5a48a4d unclassified-dotnet-tripledes-resource-loader
- 0bc60a0e1158
- 0b6a849a68a4 unclassified-pe32plus
- 0854c21ed764 unclassified-autoit-compiled
- 019d2f45acc4 unclassified-js-webdav-dropper