- 54e64e 154 samples malware-family, loader, defense-evasion, c2
- 9d2ca3 88 samples loader, malware-family, pe, mingw
- ACR Stealer 175 samples infostealer, malware-family, golang, signing
- AgentTesla 278 samples malware-family, infostealer, dotnet, smtp-exfiltration
- AnyDesk Batch Dropper Family 0 samples script, dropper, persistence, c2
- AsgardProtector 5 samples malware-family, loader, evasion, pe
- AsyncRAT 87 samples malware-family, rat, dotnet, c2
- AvalancheRunner 0 samples dotnet, loader, defense-evasion, masquerading
- ayrseushop 1 sample malware-family, infostealer, pe, compiler
- brooter 0 samples delphi, brute-force, credential-stuffing, social-engineering
- chacha8 1 sample malware-family, ransomware, file-encryptor, chacha
- ChromeLoader / Pulsar RAT 0 samples malware-family, rat, infostealer, loader
- coinminer 586 samples malware-family, cryptominer, impact, defense-evasion
- ConnectWise (ScreenConnect) abuse 347 samples malware-family, c2, defense-evasion, signing
- d52f85 92 samples malware-family, pe, msvc, loader
- darkcomet — Commodity Delphi VCL RAT family 2 samples malware-family, rat, c2, pe
- depumped — OpenCTI Umbrella Label 61 samples malware-family, attribution
- dolphin 0 samples rust, malwarerat, rat, infostealer
- esmk-crypter-loader 0 samples malware-family, loader, crypter, pe
- euone 7 samples malware-family, pe, installer, delphi
- formbook: AutoIt-delivered infostealer with shellcode bootstrap 127 samples malware-family, infostealer, autoit, obfuscation
- gcleaner 23 samples malware-family, downloader, installer, pe
- gerador-loader 0 samples malware-family, loader, pe, defense-evasion
- gh0st 6 samples rat, malware-family, pe, c2
- goloader — Go Reflective Runtime Linker Malware 0 samples loader, golang, reflective-loading, defense-evasion
- hippamsascom 7 samples malware-family, loader, pe, compiler
- IObit Driver Booster 0 samples benign, software, false-positive
- iteGroup SBS Dropper 0 samples script, dropper, c2, obfuscation
- Lazarus Group 3 samples threat-actor, attribution, malware-family, loader
- letsdiskusscom 2 samples malware-family, loader, script, nodejs
- Lummastealer 39 samples infostealer, malware-family, golang, signing
- maskgramstealer — MinGW-w64 PE64 infostealer family with runtime API resolution and Telegram C2 7 samples malware-family, infostealer, clipper, pe
- menomoushop 1 sample malware-family, infostealer, pe, compiler
- Meterpreter 3 samples malware-family, rat, c2-protocol, code-injection
- mirai 2 samples iot, botnet, ddos, arm
- NanoCore 145 samples malware-family, rat, dotnet, c2
- netsupport-inno-dropper 1 sample malware-family, loader, pe, installer
- NeuralpulseCore5SBS 1 sample infostealer, malware-family, golang, signing
- nfedigitalcom 2 samples malware-family, banker, loader, pe
- OrderReshop Stealer 1 sample infostealer, malware-family, golang, pe-overlay-parser
- Overwolf TeamSpeak Helper — Signed MSVC C++ gaming-overlay plugin, benign baseline with Authenticode by Overwolf Ltd 0 samples pe, compiler, signing, research-target
- Petpack — .NET AES-managed loader family 0 samples dotnet, malware-family, loader, obfuscation
- Phorpiex 14 samples malware-family, loader, malware-bazaar, attribution
- poabu-inno-dropper 0 samples malware-family, installer, dropper, pe
- Prometei 11 samples malware-family, cryptominer, linux, elf
- pyinstaller-pyarmor-dropper 0 samples python-pyinstaller, obfuscation, defense-evasion, pe
- Quasar 3 samples dotnet, rat, malware-family, c2
- Remcos RAT 10 samples malware-family, rat, c2, persistence
- RemotePE 0 samples malware-family, rat, c2-protocol, loader
- remusstealer 170 samples malware-family, infostealer, packer, obfuscation
- silentnet 33 samples malware-family, rat, c2, zig
- SilverFox (ValleyRAT) 147 samples malware-family, loader, rat, defense-evasion
- spamita 9 samples malware-family, script, loader, spam
- sunwukong 7 samples malware-family, loader, pe, compiler
- test 1 sample script, zip, malware-family
- unattributed 0 samples
- Unclassified AutoIt Compiled PE32 0 samples malware-family, loader, autoit, evasion
- Unclassified Batch PowerShell Dropper Family 0 samples script, dropper, c2, defense-evasion
- Unclassified Batch Self-Extract .NET Dropper 0 samples script, dropper, dotnet, obfuscation
- Unclassified Batch Skip-4 PowerShell Dropper 0 samples script, dropper, defense-evasion, execution
- Unclassified Batch String-Slice Dropper Family 0 samples script, dropper, execution, defense-evasion
- Unclassified Danish Batch PowerShell Dropper Family 0 samples script, dropper, c2, defense-evasion
- Unclassified Destructive Batch Script Family 0 samples script, impact, wipers, masquerading
- Unclassified .NET Bitmap-Stego Loader 0 samples dotnet, obfuscation, loader, bitmap-steganography
- unclassified-dotnet-chess-engine 0 samples dotnet, signing, obfuscation, social-engineering-filename-lure
- unclassified-dotnet-crypter-loader 0 samples dotnet, malware-family, loader, obfuscation
- unclassified-dotnet-game — .NET WinForms game binaries masquerading as banking/finance lures 0 samples dotnet, evasion, malware-family
- unclassified-dotnet-inventory-app 0 samples
- unclassified-dotnet-minesweeper-masquerade — .NET Framework Minesweeper game distributed under business-document filenames 0 samples dotnet, evasion, malware-family
- Unclassified .NET Native AOT Loader Family 0 samples loader, dotnet, anti-analysis, evasion
- Unclassified .NET Protobuf Loader 0 samples dotnet, malware-family, loader, c2
- unclassified-dotnet-strong-masquerade 0 samples dotnet, malware-family, loader, obfuscation
- unclassified-dotnet-transmock-masquerade 0 samples dotnet, pe, malware-family, loader
- unclassified-dotnet-tripledes-resource-loader 0 samples dotnet, malware-family, loader, obfuscation
- Unclassified .NET Whisper Loader 0 samples dotnet, loader, obfuscation, malware-family
- unclassified-dotnet 0 samples dotnet, pe, malware-family, unclassified
- unclassified-go-pe64 — Go PE64+ signed loader cluster with randomized function names; also fake source-path masquerade variant 0 samples malware-family, golang, pe, evasion
- unclassified-js-bitbucket-stego-dropper 0 samples script, malware-family, loader, obfuscation
- Unclassified JS Dropper Family 0 samples script, dropper, c2, anti-vm
- unclassified-js-german-locale-dropper 0 samples script, obfuscation, evasion, defense-evasion
- Unclassified JS Horus Dropper Family 0 samples malware-family, loader, c2, persistence
- unclassified-js-noise-base64-eval-dropper 0 samples script, obfuscation, evasion, defense-evasion
- Unclassified JS PPTX Dropper 0 samples script, dropper, c2, obfuscation
- Unclassified JS Rentry-Telegram Dropper 0 samples script, dropper, loader, reconnaissance
- Unclassified JS S3 Dropper 0 samples script, dropper, c2, loader
- Unclassified JS WebDAV Dropper 0 samples script, dropper, c2, obfuscation
- Unclassified JScript Hex+ROT Dropper Family 0 samples script, dropper, c2, defense-evasion
- unclassified-nsis-dropper 0 samples pe, dropper, evasion, signing
- unclassified-pe32-clipper — MSVC C++ x86 PE32 Telegram-relayed crypto clipper / infostealer family 0 samples malware-family, infostealer, clipper, pe
- Unclassified .NET PE32 Malware 0 samples dotnet, obfuscation, loader, infostealer
- unclassified-pe32-nfe-loader 0 samples malware-family, loader, dropper, pe
- Unclassified PE32 0 samples pe, malware-family, loader, evasion
- Unclassified PE32+ — large MSVC C++ binaries with TLS callbacks and minimal IAT 0 samples malware-family, loader, pe, compiler
- Unclassified PE64 Clipper — MinGW-w64 infostealer with wallet regex and Telegram user ID 0 samples malware-family, infostealer, clipper, pe
- Unclassified Python ngrok RAT Family 0 samples script, rat, c2, credential-access
- unclassified-rust-dropper-2024 0 samples rust, loader, dropper, c2
- uniqfile 23 samples malware-family, pe, compiler, golang
- ValleyRAT 55 samples malware-family, rat, dotnet, c2
- Vidar 260 samples infostealer, windows, golang, msvc
- WannaCry 15 samples malware-family, ransomware, impact, lateral-movement
- XenoRAT 2 samples malware-family, rat, dotnet, c2
- ZENCONNEKT 0 samples malware-family, rat, golang, c2-protocol