PP PACKETPURSUIT
  • Home
  • About
  • Projects
  • Intel
  • Blog
  • Vault
  • Contact

> Families_

~/packetpursuit $ ls /intel/families/

intel / families
  • 54e64e 298 samples malware-family, loader, defense-evasion, c2
  • 9d2ca3 149 samples loader, malware-family, pe, mingw
  • ACR Stealer 241 samples infostealer, malware-family, golang, signing
  • AFK Stealer 0 samples malware-family, infostealer, rat, go
  • AgentTesla 476 samples malware-family, infostealer, dotnet, smtp-exfiltration
  • AnyDesk Batch Dropper Family 0 samples script, dropper, persistence, c2
  • AsgardProtector 20 samples malware-family, loader, evasion, pe
  • AsyncRAT 204 samples malware-family, rat, dotnet, c2
  • AvalancheRunner 0 samples dotnet, loader, defense-evasion, masquerading
  • ayrseushop 1 sample malware-family, infostealer, pe, compiler
  • BlackMatter 31 samples malware-family, loader, ransomware, malware-bazaar
  • BlankGrabber 11 samples malware-family, infostealer, python-pyinstaller, c2
  • bromechokucom 1 sample malware-family, delphi, banking-trojan, latam
  • brooter 0 samples delphi, brute-force, credential-stuffing, social-engineering
  • chacha8 1 sample malware-family, ransomware, file-encryptor, chacha
  • ChromeLoader / Pulsar RAT 0 samples malware-family, rat, infostealer, loader
  • ClickFix 859 samples malware-family, loader, browser-extension, defense-evasion
  • cloud55filecc — Contested OpenCTI label 9 samples malware-family, infostealer, golang, signing
  • coinminer 893 samples malware-family, cryptominer, impact, defense-evasion
  • ConnectWise (ScreenConnect) abuse 593 samples malware-family, c2, defense-evasion, signing
  • d52f85 135 samples malware-family, pe, msvc, themida
  • darkcomet — Commodity Delphi VCL RAT family 2 samples malware-family, rat, c2, pe
  • depumped 84 samples umbrella, contested, opencti
  • dolphin 0 samples rust, malwarerat, rat, infostealer
  • esmk-crypter-loader 0 samples malware-family, loader, crypter, pe
  • euone 7 samples malware-family, pe, installer, delphi
  • exeinarchive 5 samples malware-family, script, dropper, spam
  • formbook: AutoIt-delivered infostealer with shellcode bootstrap 257 samples malware-family, infostealer, autoit, obfuscation
  • ftpcrack 0 samples malware-family, python-pyinstaller, credential-theft, impact
  • gcleaner 39 samples malware-family, downloader, installer, pe
  • gerador-loader 0 samples malware-family, loader, pe, defense-evasion
  • gh0st 10 samples rat, malware-family, pe, c2
  • gh0strat 23 samples malware-family, rat, loader, c2
  • GhostPulse 49 samples malware-family, loader, qt5, pe
  • goloader — Go Reflective Runtime Linker Malware 0 samples loader, golang, reflective-loading, defense-evasion
  • hippamsascom 7 samples malware-family, loader, pe, compiler
  • IObit Driver Booster 0 samples benign, software, false-positive
  • iteGroup SBS Dropper 0 samples script, dropper, c2, obfuscation
  • Lazarus Group 3 samples threat-actor, attribution, malware-family, loader
  • letsdiskusscom 2 samples
  • Lummastealer 56 samples infostealer, malware-family, golang, signing
  • maskgramstealer — MinGW-w64 PE64 infostealer family with runtime API resolution and Telegram C2 7 samples malware-family, infostealer, clipper, pe
  • menomoushop 1 sample malware-family, infostealer, pe, compiler
  • meshcentral-agent-dropper 0 samples malware-family, downloader, installer, pe
  • Meterpreter 3 samples malware-family, rat, c2-protocol, code-injection
  • mirai 296 samples iot, botnet, ddos, arm
  • Moonshine AOT Loader Family 0 samples loader, dotnet, anti-analysis, evasion
  • NanoCore 201 samples malware-family, rat, dotnet, c2
  • netsupport-inno-dropper 1 sample malware-family, loader, pe, installer
  • NeuralpulseCore5SBS 1 sample infostealer, malware-family, golang, signing
  • nfedigitalcom 2 samples malware-family, banker, loader, pe
  • Nova Shadow — French-language JavaScript RAT/stealer family 1 sample malware-family, rat, infostealer, c2
  • OrderReshop Stealer 1 sample infostealer, malware-family, golang, pe-overlay-parser
  • Overwolf TeamSpeak Helper — Signed MSVC C++ gaming-overlay plugin, benign baseline with Authenticode by Overwolf Ltd 0 samples pe, compiler, signing, research-target
  • Pay2Key 0 samples
  • Petpack — .NET AES-managed loader family 0 samples dotnet, malware-family, loader, obfuscation
  • Phorpiex 33 samples malware-family, loader, malware-bazaar, attribution
  • poabu-inno-dropper 0 samples malware-family, installer, dropper, pe
  • Prometei 19 samples malware-family, cryptominer, linux, elf
  • pyinstaller-pyarmor-dropper 0 samples python-pyinstaller, obfuscation, defense-evasion, pe
  • Quasar 4 samples dotnet, rat, malware-family, c2
  • ratonrat 22 samples dotnet, rat, infostealer, c2
  • Remcos RAT 11 samples malware-family, rat, c2, persistence
  • RemotePE 0 samples malware-family, rat, c2-protocol, loader
  • remusstealer 348 samples infostealer, malware-family, golang, contested
  • rustystealer — Rust x64 crypto clipboard clipper family (also known as xeno_clipper) 26 samples malware-family, infostealer, clipper, pe
  • Setup Factory Dropper 0 samples malware-family, loader, defense-evasion, social-engineering
  • silentnet 45 samples malware-family, rat, c2, zig
  • SilverFox (ValleyRAT) 296 samples malware-family, loader, rat, defense-evasion
  • sky_jamaica 0 samples malware-family, banking-trojan, latam, dotnet
  • spamita 12 samples malware-family, script, loader, spam
  • Stealc 150 samples infostealer, malware-family, c2, exfiltration
  • sunwukong 8 samples malware-family, loader, pe, compiler
  • test 1 sample script, zip, malware-family
  • tofsee 16 samples malware-family, spam, botnet, loader
  • unattributed 0 samples
  • unclassified-autoit-compiled 0 samples autoit, infostealer, compiled
  • Unclassified Batch PowerShell Dropper Family 0 samples script, dropper, c2, defense-evasion
  • Unclassified Batch Self-Extract .NET Dropper 0 samples script, dropper, dotnet, obfuscation
  • Unclassified Batch Skip-4 PowerShell Dropper 0 samples script, dropper, defense-evasion, execution
  • Unclassified Batch String-Slice Dropper Family 0 samples script, dropper, execution, defense-evasion
  • Unclassified Danish Batch PowerShell Dropper Family 0 samples script, dropper, c2, defense-evasion
  • Unclassified Destructive Batch Script Family 0 samples script, impact, wipers, masquerading
  • unclassified-dotnet-bee-themed-rasterizer 0 samples dotnet, malware-family, social-engineering-filename-lure, version-info-masquerade
  • Unclassified .NET Bitmap-Stego Loader 0 samples dotnet, obfuscation, loader, bitmap-steganography
  • unclassified-dotnet-chess-engine 0 samples dotnet, signing, obfuscation, social-engineering-filename-lure
  • unclassified-dotnet-crypter-loader 0 samples dotnet, malware-family, loader, obfuscation
  • unclassified-dotnet-game — .NET WinForms game binaries masquerading as banking/finance lures 0 samples dotnet, evasion, malware-family
  • unclassified-dotnet-inventory-app 0 samples
  • unclassified-dotnet-minesweeper-masquerade — .NET Framework Minesweeper game distributed under business-document filenames 0 samples dotnet, evasion, malware-family
  • Unclassified .NET Native AOT Loader Family 0 samples loader, dotnet, anti-analysis, evasion
  • Unclassified .NET Protobuf Loader 0 samples dotnet, malware-family, loader, c2
  • unclassified-dotnet-rijndael-md5-resource-loader 0 samples dotnet, malware-family, loader, obfuscation
  • unclassified-dotnet-strong-masquerade 0 samples dotnet, malware-family, loader, obfuscation
  • unclassified-dotnet-transmock-masquerade 0 samples dotnet, pe, malware-family, loader
  • unclassified-dotnet-tripledes-resource-loader 0 samples dotnet, malware-family, loader, obfuscation
  • Unclassified .NET Whisper Loader 0 samples dotnet, loader, obfuscation, malware-family
  • unclassified-dotnet 0 samples dotnet, pe, malware-family, unclassified
  • unclassified-go-pe32 — Go PE32 x86 cluster with garbled main.* function names 0 samples malware-family, golang, pe, evasion
  • unclassified-go-pe64 — Go PE64+ signed loader cluster with randomized function names; also fake source-path masquerade variant 0 samples malware-family, golang, pe, evasion
  • unclassified-js-bitbucket-stego-dropper 0 samples script, malware-family, loader, obfuscation
  • unclassified-js-cjk-stego-dropper 0 samples
  • Unclassified JS Dropper Family 0 samples script, dropper, c2, anti-vm
  • unclassified-js-german-locale-dropper 0 samples script, obfuscation, evasion, defense-evasion
  • Unclassified JS Horus Dropper Family 0 samples malware-family, loader, c2, persistence
  • unclassified-js-noise-base64-eval-dropper 0 samples script, obfuscation, evasion, defense-evasion
  • Unclassified JS PPTX Dropper 0 samples script, dropper, c2, obfuscation
  • Unclassified JS Rentry-Telegram Dropper 0 samples script, dropper, loader, reconnaissance
  • Unclassified JS S3 Dropper 0 samples script, dropper, c2, loader
  • Unclassified JS WebDAV Dropper 0 samples script, dropper, c2, obfuscation
  • Unclassified JScript Hex+ROT Dropper Family 0 samples script, dropper, c2, defense-evasion
  • unclassified-mingw64-https-stager 0 samples
  • unclassified-msvc-browser-credential-harvester 0 samples infostealer, malware-family, compiler, c2
  • unclassified-nsis-dropper 0 samples pe, dropper, evasion, signing
  • unclassified-pe32-clipper — MSVC C++ x86 PE32 Telegram-relayed crypto clipper / infostealer family 0 samples malware-family, infostealer, clipper, pe
  • Unclassified .NET PE32 Malware 0 samples dotnet, obfuscation, loader, infostealer
  • unclassified-pe32-nfe-loader 0 samples malware-family, loader, dropper, pe
  • Unclassified PE32 0 samples pe, malware-family, loader, evasion
  • Unclassified PE32+ — large MSVC C++ binaries with TLS callbacks and minimal IAT 0 samples malware-family, loader, pe, compiler
  • Unclassified PE64 Clipper — MinGW-w64 infostealer with wallet regex and Telegram user ID 0 samples malware-family, infostealer, clipper, pe
  • unclassified-pe64-modular-builder 0 samples malware-family, pe, compiler, c2
  • Unclassified Python ngrok RAT Family 0 samples script, rat, c2, credential-access
  • Unclassified Rouki-OBFUSCATOR Batch Dropper Family 0 samples script, dropper, obfuscation, defense-evasion
  • unclassified-rust-dropper-2024 0 samples rust, loader, dropper, c2
  • uniqfile 31 samples malware-family, pe, compiler, golang
  • us0file 44 samples malware-family, crypter, loader, pe
  • valetgate 0 samples malware-family, rat, pe32plus, mingw
  • ValleyRAT 144 samples malware-family, rat, dotnet, c2
  • Vidar 1375 samples infostealer, windows, golang, msvc
  • WannaCry 15 samples malware-family, ransomware, impact, lateral-movement
  • Wraith 12 samples malware-family, pe, c2, defense-evasion
  • XenoRAT 4 samples malware-family, rat, dotnet, c2
  • XLABB Grabber 0 samples infostealer, python, pyinstaller, discord-webhook
  • xloader: XLoader infostealer family 0 samples malware-family, infostealer, loader, script
  • xryus-inno-dropper 0 samples malware-family, loader, pe, installer
  • ZENCONNEKT 0 samples malware-family, rat, golang, c2-protocol

© 2026 PacketPursuit | Jacob Wills | recon | exploit && defend | repeat >> theGrind.log | status