- 54e64e 298 samples malware-family, loader, defense-evasion, c2
- 9d2ca3 149 samples loader, malware-family, pe, mingw
- ACR Stealer 241 samples infostealer, malware-family, golang, signing
- AFK Stealer 0 samples malware-family, infostealer, rat, go
- AgentTesla 476 samples malware-family, infostealer, dotnet, smtp-exfiltration
- AnyDesk Batch Dropper Family 0 samples script, dropper, persistence, c2
- AsgardProtector 20 samples malware-family, loader, evasion, pe
- AsyncRAT 204 samples malware-family, rat, dotnet, c2
- AvalancheRunner 0 samples dotnet, loader, defense-evasion, masquerading
- ayrseushop 1 sample malware-family, infostealer, pe, compiler
- BlackMatter 31 samples malware-family, loader, ransomware, malware-bazaar
- BlankGrabber 11 samples malware-family, infostealer, python-pyinstaller, c2
- bromechokucom 1 sample malware-family, delphi, banking-trojan, latam
- brooter 0 samples delphi, brute-force, credential-stuffing, social-engineering
- chacha8 1 sample malware-family, ransomware, file-encryptor, chacha
- ChromeLoader / Pulsar RAT 0 samples malware-family, rat, infostealer, loader
- ClickFix 859 samples malware-family, loader, browser-extension, defense-evasion
- cloud55filecc — Contested OpenCTI label 9 samples malware-family, infostealer, golang, signing
- coinminer 893 samples malware-family, cryptominer, impact, defense-evasion
- ConnectWise (ScreenConnect) abuse 593 samples malware-family, c2, defense-evasion, signing
- d52f85 135 samples malware-family, pe, msvc, themida
- darkcomet — Commodity Delphi VCL RAT family 2 samples malware-family, rat, c2, pe
- depumped 84 samples umbrella, contested, opencti
- dolphin 0 samples rust, malwarerat, rat, infostealer
- esmk-crypter-loader 0 samples malware-family, loader, crypter, pe
- euone 7 samples malware-family, pe, installer, delphi
- exeinarchive 5 samples malware-family, script, dropper, spam
- formbook: AutoIt-delivered infostealer with shellcode bootstrap 257 samples malware-family, infostealer, autoit, obfuscation
- ftpcrack 0 samples malware-family, python-pyinstaller, credential-theft, impact
- gcleaner 39 samples malware-family, downloader, installer, pe
- gerador-loader 0 samples malware-family, loader, pe, defense-evasion
- gh0st 10 samples rat, malware-family, pe, c2
- gh0strat 23 samples malware-family, rat, loader, c2
- GhostPulse 49 samples malware-family, loader, qt5, pe
- goloader — Go Reflective Runtime Linker Malware 0 samples loader, golang, reflective-loading, defense-evasion
- hippamsascom 7 samples malware-family, loader, pe, compiler
- IObit Driver Booster 0 samples benign, software, false-positive
- iteGroup SBS Dropper 0 samples script, dropper, c2, obfuscation
- Lazarus Group 3 samples threat-actor, attribution, malware-family, loader
- letsdiskusscom 2 samples
- Lummastealer 56 samples infostealer, malware-family, golang, signing
- maskgramstealer — MinGW-w64 PE64 infostealer family with runtime API resolution and Telegram C2 7 samples malware-family, infostealer, clipper, pe
- menomoushop 1 sample malware-family, infostealer, pe, compiler
- meshcentral-agent-dropper 0 samples malware-family, downloader, installer, pe
- Meterpreter 3 samples malware-family, rat, c2-protocol, code-injection
- mirai 296 samples iot, botnet, ddos, arm
- Moonshine AOT Loader Family 0 samples loader, dotnet, anti-analysis, evasion
- NanoCore 201 samples malware-family, rat, dotnet, c2
- netsupport-inno-dropper 1 sample malware-family, loader, pe, installer
- NeuralpulseCore5SBS 1 sample infostealer, malware-family, golang, signing
- nfedigitalcom 2 samples malware-family, banker, loader, pe
- Nova Shadow — French-language JavaScript RAT/stealer family 1 sample malware-family, rat, infostealer, c2
- OrderReshop Stealer 1 sample infostealer, malware-family, golang, pe-overlay-parser
- Overwolf TeamSpeak Helper — Signed MSVC C++ gaming-overlay plugin, benign baseline with Authenticode by Overwolf Ltd 0 samples pe, compiler, signing, research-target
- Pay2Key 0 samples
- Petpack — .NET AES-managed loader family 0 samples dotnet, malware-family, loader, obfuscation
- Phorpiex 33 samples malware-family, loader, malware-bazaar, attribution
- poabu-inno-dropper 0 samples malware-family, installer, dropper, pe
- Prometei 19 samples malware-family, cryptominer, linux, elf
- pyinstaller-pyarmor-dropper 0 samples python-pyinstaller, obfuscation, defense-evasion, pe
- Quasar 4 samples dotnet, rat, malware-family, c2
- ratonrat 22 samples dotnet, rat, infostealer, c2
- Remcos RAT 11 samples malware-family, rat, c2, persistence
- RemotePE 0 samples malware-family, rat, c2-protocol, loader
- remusstealer 348 samples infostealer, malware-family, golang, contested
- rustystealer — Rust x64 crypto clipboard clipper family (also known as xeno_clipper) 26 samples malware-family, infostealer, clipper, pe
- Setup Factory Dropper 0 samples malware-family, loader, defense-evasion, social-engineering
- silentnet 45 samples malware-family, rat, c2, zig
- SilverFox (ValleyRAT) 296 samples malware-family, loader, rat, defense-evasion
- sky_jamaica 0 samples malware-family, banking-trojan, latam, dotnet
- spamita 12 samples malware-family, script, loader, spam
- Stealc 150 samples infostealer, malware-family, c2, exfiltration
- sunwukong 8 samples malware-family, loader, pe, compiler
- test 1 sample script, zip, malware-family
- tofsee 16 samples malware-family, spam, botnet, loader
- unattributed 0 samples
- unclassified-autoit-compiled 0 samples autoit, infostealer, compiled
- Unclassified Batch PowerShell Dropper Family 0 samples script, dropper, c2, defense-evasion
- Unclassified Batch Self-Extract .NET Dropper 0 samples script, dropper, dotnet, obfuscation
- Unclassified Batch Skip-4 PowerShell Dropper 0 samples script, dropper, defense-evasion, execution
- Unclassified Batch String-Slice Dropper Family 0 samples script, dropper, execution, defense-evasion
- Unclassified Danish Batch PowerShell Dropper Family 0 samples script, dropper, c2, defense-evasion
- Unclassified Destructive Batch Script Family 0 samples script, impact, wipers, masquerading
- unclassified-dotnet-bee-themed-rasterizer 0 samples dotnet, malware-family, social-engineering-filename-lure, version-info-masquerade
- Unclassified .NET Bitmap-Stego Loader 0 samples dotnet, obfuscation, loader, bitmap-steganography
- unclassified-dotnet-chess-engine 0 samples dotnet, signing, obfuscation, social-engineering-filename-lure
- unclassified-dotnet-crypter-loader 0 samples dotnet, malware-family, loader, obfuscation
- unclassified-dotnet-game — .NET WinForms game binaries masquerading as banking/finance lures 0 samples dotnet, evasion, malware-family
- unclassified-dotnet-inventory-app 0 samples
- unclassified-dotnet-minesweeper-masquerade — .NET Framework Minesweeper game distributed under business-document filenames 0 samples dotnet, evasion, malware-family
- Unclassified .NET Native AOT Loader Family 0 samples loader, dotnet, anti-analysis, evasion
- Unclassified .NET Protobuf Loader 0 samples dotnet, malware-family, loader, c2
- unclassified-dotnet-rijndael-md5-resource-loader 0 samples dotnet, malware-family, loader, obfuscation
- unclassified-dotnet-strong-masquerade 0 samples dotnet, malware-family, loader, obfuscation
- unclassified-dotnet-transmock-masquerade 0 samples dotnet, pe, malware-family, loader
- unclassified-dotnet-tripledes-resource-loader 0 samples dotnet, malware-family, loader, obfuscation
- Unclassified .NET Whisper Loader 0 samples dotnet, loader, obfuscation, malware-family
- unclassified-dotnet 0 samples dotnet, pe, malware-family, unclassified
- unclassified-go-pe32 — Go PE32 x86 cluster with garbled main.* function names 0 samples malware-family, golang, pe, evasion
- unclassified-go-pe64 — Go PE64+ signed loader cluster with randomized function names; also fake source-path masquerade variant 0 samples malware-family, golang, pe, evasion
- unclassified-js-bitbucket-stego-dropper 0 samples script, malware-family, loader, obfuscation
- unclassified-js-cjk-stego-dropper 0 samples
- Unclassified JS Dropper Family 0 samples script, dropper, c2, anti-vm
- unclassified-js-german-locale-dropper 0 samples script, obfuscation, evasion, defense-evasion
- Unclassified JS Horus Dropper Family 0 samples malware-family, loader, c2, persistence
- unclassified-js-noise-base64-eval-dropper 0 samples script, obfuscation, evasion, defense-evasion
- Unclassified JS PPTX Dropper 0 samples script, dropper, c2, obfuscation
- Unclassified JS Rentry-Telegram Dropper 0 samples script, dropper, loader, reconnaissance
- Unclassified JS S3 Dropper 0 samples script, dropper, c2, loader
- Unclassified JS WebDAV Dropper 0 samples script, dropper, c2, obfuscation
- Unclassified JScript Hex+ROT Dropper Family 0 samples script, dropper, c2, defense-evasion
- unclassified-mingw64-https-stager 0 samples
- unclassified-msvc-browser-credential-harvester 0 samples infostealer, malware-family, compiler, c2
- unclassified-nsis-dropper 0 samples pe, dropper, evasion, signing
- unclassified-pe32-clipper — MSVC C++ x86 PE32 Telegram-relayed crypto clipper / infostealer family 0 samples malware-family, infostealer, clipper, pe
- Unclassified .NET PE32 Malware 0 samples dotnet, obfuscation, loader, infostealer
- unclassified-pe32-nfe-loader 0 samples malware-family, loader, dropper, pe
- Unclassified PE32 0 samples pe, malware-family, loader, evasion
- Unclassified PE32+ — large MSVC C++ binaries with TLS callbacks and minimal IAT 0 samples malware-family, loader, pe, compiler
- Unclassified PE64 Clipper — MinGW-w64 infostealer with wallet regex and Telegram user ID 0 samples malware-family, infostealer, clipper, pe
- unclassified-pe64-modular-builder 0 samples malware-family, pe, compiler, c2
- Unclassified Python ngrok RAT Family 0 samples script, rat, c2, credential-access
- Unclassified Rouki-OBFUSCATOR Batch Dropper Family 0 samples script, dropper, obfuscation, defense-evasion
- unclassified-rust-dropper-2024 0 samples rust, loader, dropper, c2
- uniqfile 31 samples malware-family, pe, compiler, golang
- us0file 44 samples malware-family, crypter, loader, pe
- valetgate 0 samples malware-family, rat, pe32plus, mingw
- ValleyRAT 144 samples malware-family, rat, dotnet, c2
- Vidar 1375 samples infostealer, windows, golang, msvc
- WannaCry 15 samples malware-family, ransomware, impact, lateral-movement
- Wraith 12 samples malware-family, pe, c2, defense-evasion
- XenoRAT 4 samples malware-family, rat, dotnet, c2
- XLABB Grabber 0 samples infostealer, python, pyinstaller, discord-webhook
- xloader: XLoader infostealer family 0 samples malware-family, infostealer, loader, script
- xryus-inno-dropper 0 samples malware-family, loader, pe, installer
- ZENCONNEKT 0 samples malware-family, rat, golang, c2-protocol