################################################################ # ThreatFox IOCs: recent SHA256 hashes - CSV format # # Last updated: 2024-04-24 15:17:08 UTC # # # # Terms Of Use: https://threatfox.abuse.ch/faq/#tos # # For questions please contact threatfox [at] abuse.ch # ################################################################ # # "first_seen_utc","ioc_id","ioc_value","ioc_type","threat_type","fk_malware","malware_alias","malware_printable","last_seen_utc","confidence_level","reference","tags","anonymous","reporter" "2024-04-24 15:17:08", "1262097", "500b51771f03e61f1c46fc29c2a786201c123ae5f0369bd1664992bd7c434a30", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:17:05", "1262094", "37fcb2df95b2ba1bc601c6140b1d415ba362ea67834bc13d1eaebbb69a1e5f68", "sha256_hash", "payload", "win.netwire", "NetWeird,NetWire,Recam", "NetWire RC", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:17:02", "1262091", "1f204b43acfdf5d1088f37b2159d98d5500bdaeec99cd3f0d6e8ceb77282351b", "sha256_hash", "payload", "win.asyncrat", "None", "AsyncRAT", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:59", "1262088", "b019a47dc528a7197129adec69ea6813c28e60884c267cd297524296861a9ed6", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:56", "1262085", "ece58cdda5d85a7fe7d7262313b8041e3c988d814b7dd60f0468dbb7109596ba", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:53", "1262082", "fd15b9b162dcbe4f16157d4b13f69a6b2ede55fcd5ddb2a19bce8eb68a363e43", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:50", "1262079", "c96565623c3e405a370614f452383a763f5a48baf25e79f91a6311c9a0a8fd3a", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:47", "1262076", "5b88fdc4c1564305f8883e5ec48cadea105d082a5a1bae6a17c57c81c01069a7", "sha256_hash", "payload", "win.strelastealer", "None", "StrelaStealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:44", "1262073", "651bf6dc2ce11fbbda045ac186ab58ac3d691f8d28dc811f2b1552fe74b275cc", "sha256_hash", "payload", "win.teambot", "FINTEAM", "TeamBot", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:41", "1262070", "dc09ed4ade0b108f9774523d064a9a074f46248f1fd42651ba6fb17820e6a417", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:38", "1262067", "d7531e4728438f15714cd44a6ed353d5117b4a3b6db1ece8b945ca8eb0b1408d", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:35", "1262065", "8b3133696ef1e7609974f8084f6ca977ab74db7c688fa7b8df83b2e9231f1764", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:32", "1262062", "ae9f157e9ac6956863d36c82f45f27fa14fa6f78ad98ba73218593b5d32f44c6", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:29", "1262059", "8987f3cd89bd9f739ef4ee2495ccd81be89cf7d5f52b445c94920cfae3b0fc27", "sha256_hash", "payload", "win.sigloader", "None", "SigLoader", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:26", "1262056", "3a9444944c737900563b16dab76e19bcd2c52f1d3b35e258d581b523586ae828", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:23", "1262053", "a11d36f9f4b69fd1e6c13584455e6270fd906530ad6e034d67927c16cbc76586", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:20", "1262050", "a6db9168b669e03a0ba63baabd96c00882a9cb6de95e0945993fd720b8cfd391", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:15", "1262047", "5f8e6d5fd79a5a648e42597881ddf5e418be34a81b678b9742fad39d6b74c298", "sha256_hash", "payload", "win.krakenkeylogger", "None", "KrakenKeylogger", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:12", "1262044", "04d2e21d12836aeb42dea69f39783165668427397987d8ce55c94765effb844b", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:09", "1262041", "0766dcf703dbf0243d873fff3b325054eee96ce58a9753ac8aa9891c311b4434", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:06", "1262038", "994b994e9983a7f21d0a106090efe4485b39a23dd4d4f086bba3925208c80d01", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:16:02", "1262035", "8df5ecbc8ea978c98c9c3a0918fe9ee233f169ee9e3d38855b7da8fc96aad8dc", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:59", "1262032", "7fee503438f90d0206012674566587b5ecef1d040935809ae308b12842dc6196", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:55", "1262029", "061087cd835abcfc3411f0ec4b15ccf80516276a356b2eedc4cb444d0dac0187", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:52", "1262026", "15113629d65d474d78089e91ee269220b68fdcff8c4df46ea1da0af21cd559e3", "sha256_hash", "payload", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:49", "1262023", "e1cecfcc4eed2f4b74af7d971dcf24555534db164ddb0b7cd1e821b2f0402703", "sha256_hash", "payload", "win.dbatloader", "ModiLoader,NatsoLoader", "DBatLoader", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:45", "1262020", "86e17aa882c690ede284f3e445439dfe589d8f36e31cbc09d102305499d5c498", "sha256_hash", "payload", "win.lockbit", "ABCD Ransomware", "LockBit", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:42", "1262017", "48ca70c01e870434304ccd508ef88d824b8d3c9588c990402dae450a5e56f73c", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:38", "1262014", "6c0bd6cae657449a07dcb78940ea732d7e4e24546477b083116bff4c99bd417d", "sha256_hash", "payload", "win.stop", "KeyPass,Djvu", "STOP", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:34", "1262011", "97f689bdc4e9fd3ad22d44f57b2d80f26813b67bddcd816fe4de63a7721be893", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:31", "1262008", "e3e2106835618398ef240b9e3e84026a0019bafda4464f3150756d42c5374f9d", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:27", "1262004", "89d7f5ebd276fd6f53eacfef8377c6756a4da4c964da2bb51e059d5f04001b2c", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:23", "1262001", "11cdeed6025daa716961f06ea3b1820270c21a0e5c633c91dc8b547b753c8681", "sha256_hash", "payload", "win.metastealer", "None", "MetaStealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:19", "1261998", "0823c2f58d094e1c096ae9184acf0b930df6dff97d0cd77728dc3ff07f9c0096", "sha256_hash", "payload", "win.troystealer", "None", "troystealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:15", "1261995", "8afec5473dd48de87edaf7e4fbd34005441fd5214fe562f92f2113796603eb0b", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:08", "1261992", "8e53393db26258fb917fd570861070420d31148c2826dcdbed52ce326c2d5ff6", "sha256_hash", "payload", "win.stop", "KeyPass,Djvu", "STOP", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:15:01", "1261989", "19640f20d067c8ca1ba3e08d34ea493c05b99016c6608dbcbfdf848ca4d60452", "sha256_hash", "payload", "win.strelastealer", "None", "StrelaStealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:57", "1261986", "64da1a2af5fbbd35867312aa68bfedd2dc695cf8bdac16e6974237226ebb8cc0", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:54", "1261983", "ec7dd08d03d5d4142c82fc04cea7e948d05641b0a3008a0d8a00b0421b5b04f9", "sha256_hash", "payload", "win.phorpiex", "Trik,phorphiex", "Phorpiex", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:50", "1261980", "7f92d23e392f6c18a682adfe0b7df82d2972983be07d6844554b1025aa39a503", "sha256_hash", "payload", "win.strelastealer", "None", "StrelaStealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:47", "1261977", "8980e6e2628b4103f4e3e0b01365a5e9a7df6e38c067c93633371c94b3d5dd34", "sha256_hash", "payload", "win.krakenkeylogger", "None", "KrakenKeylogger", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:44", "1261974", "7151fdf1eb6797e332cdd21c6084e1b338f84fb6652284599370cf609776a676", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:40", "1261971", "200690de2b973c6f7a702d5129dea09aec57d548cab07e19f012e5a8e0c6ae64", "sha256_hash", "payload", "win.stop", "KeyPass,Djvu", "STOP", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:37", "1261968", "0f646539e424b78145f10890170c52f952ef950c3530b3b36979ea805d1c3b22", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:34", "1261965", "945a7283148a1fb1d96ccdd8eb5d69245ed7ddc37c34a709c198e5ad1689f914", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:29", "1261962", "f5f93fd662d6d3d55c5c47ead5a931ed8eb8a066d9bd29113903506e7cf56fdb", "sha256_hash", "payload", "win.strelastealer", "None", "StrelaStealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:26", "1261959", "42ac8e7e9df9877af1382f5626fd74e63210d307f6d577cd5b387ffd0c9520bd", "sha256_hash", "payload", "win.dbatloader", "ModiLoader,NatsoLoader", "DBatLoader", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:23", "1261956", "df8c1264b7ae61e5fca5741a1ca4e2800e96f8dc316e2d13d7088ad58aa3229a", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:20", "1261953", "000bdfb41a0f35b6c7a0db812e0f6a4eae13277789a58f76f978680912d83b80", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:16", "1261950", "d59649332816fca2c74de3d04445fcc521e6d3c26d7b9b753c6a3ad98146d1b6", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:13", "1261947", "444cf71032e7c7be2a79255af4fb38bab0333fb0a060ecc3fe91473d26ebce83", "sha256_hash", "payload", "win.stop", "KeyPass,Djvu", "STOP", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:09", "1261944", "3fb935f3b274dddf25a926967ceb573ad0f990bff966583157849545c60c42e4", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:06", "1261941", "a9fa586fb62d05caf2175e13fc20c8cb245d4902961bb833c8792befd5e7b0c6", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:14:03", "1261938", "5058d869c59bfb3480d1dc6f8f51d191adb890039c89ff9fd668fe7b481099b8", "sha256_hash", "payload", "win.mimikatz", "None", "MimiKatz", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:59", "1261935", "91d1e460f32ef1914084e1cae335c4de321d1b69af18632eb80a55b924fca91d", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:55", "1261932", "0d28a4525dba00368e0a1a146b0c1e75656215338358a7dbd65ee5ca2508cacf", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:52", "1261929", "4ae2e13993a8ef1fbaf538b4da18eca6e0b5ada918cbeb256c8490f6fc3b34fc", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:49", "1261926", "ee6abaf8f2f79738e67078b4286db1f91df895cef76b5657e847fad9364a5cd6", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:46", "1261923", "bc07d7fdfb816ef511fe03f6c877150430e3f4c0d1929efd1c71cf81083f1e43", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:43", "1261920", "a0a0fb07e86f86daca2883b96c5e33752eb4cbd08778bce91c40285efbc4e92f", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:40", "1261917", "efa6ac55f8dbc8d81f1d82226090b0e7c84fac9a53bf597cbaa6623aff49310d", "sha256_hash", "payload", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:37", "1261914", "c305dc9e2de49fecff28d19facee4e30fc568cbd04594f328c60301b1744387d", "sha256_hash", "payload", "win.quasar_rat", "CinaRAT,QuasarRAT,Yggdrasil", "Quasar RAT", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:34", "1261911", "d7603ee9b4ae922bee366a81374ad3234851c93f78a22023cc612dc0e148b816", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:28", "1261908", "5e0a9b8f7175b983c012fa530bb29693cd8aadf2b2feb0f56d1c089fac20edb4", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:25", "1261905", "62623bddab0911eca4cd33135383761dbcf6f22a480eda9761becf638f1c4546", "sha256_hash", "payload", "win.stop", "KeyPass,Djvu", "STOP", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:21", "1261902", "53e9bec7369824cc6c1c0823afd428d6c8b3156870527b72916c1cb898e3f43d", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:18", "1261899", "5a7b8feb65ff7cfc058c5e7198d5287ed8287ef23f721949bfba41d1cd19467c", "sha256_hash", "payload", "win.troystealer", "None", "troystealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:15", "1261896", "2f48e39c1fa623b569c7580066026dc25e629fcd4a9cdb8a58d22e45c9eb99c2", "sha256_hash", "payload", "win.stop", "KeyPass,Djvu", "STOP", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:12", "1261893", "0f4185aed646dcc354f61968b69d25e06fdb3fe3e6bab9b52e2ecce1395f667f", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:09", "1261890", "a2b803974fcfb65e21fa1a7690eb2a4822f091a8bdf45786e2085c833871d5a0", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:06", "1261887", "36dd06fa770b353aa0716188d181d371300a847b6867878f4cf15c5b6b40d751", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:03", "1261884", "ce8c0c6f213445d5bc40441e171cb112c92bd4192783c06cdd17ba4d851565f8", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:13:00", "1261881", "f6a6765642f0f8c4b81f45d4e1a9f65505432bbf4c249fa3c96b82d9c712effe", "sha256_hash", "payload", "win.stop", "KeyPass,Djvu", "STOP", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:12:57", "1261878", "5afafb07f36ae38b071a7f1be9e675f29f15472a2c9cd4963bfa6f01ba728932", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:12:54", "1261875", "c2886ea3aee978297806940b8e8c4c9e8be23bb9ff8f039be91c040bdc5f3a62", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:12:51", "1261872", "09570f445a9a80479957a36ea2e038800d5a01acf338793274f936c108f21f24", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:12:47", "1261869", "034a3732828ad09b79a12c66bf7eee3058427808bdae8b19291fffc828ee1fbf", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-24 15:12:45", "1261866", "b7abfce92efecdb6b034b4474668dc7cc08aaf7a8b6490fd3eb0fb5506024577", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2024-04-23 16:43:05", "1260804", "3d967daeab27fd5db00597456a68e350b1f164c4009147ca896b557e115d9709", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:51", "1260797", "bfd4c448793fdb2035092c40c2521b0f0ef76ccb882c2e2fbb9420cdc08db5f2", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:48", "1260794", "0a6e0a8505b349359dc63cc92fc46f879f19f43c246eb7e2445dcaca526d70fb", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:46:24", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:45", "1260791", "914a13f86d053e8296256aa5b710e50360b3816ad216d6a9b86252ecc2dd0dd0", "sha256_hash", "payload", "win.meterpreter", "None", "Meterpreter", "2024-04-23 16:46:21", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:42", "1260788", "8f54aafcf8151c437f44f4b03cff8dfb52102df7c3e1c0e7d414dbc675b25d6e", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:46:19", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:40", "1260785", "574f282bee0927e2582139d6c6ef565c10e49d5187dc87625aecfeb66d61105f", "sha256_hash", "payload", "win.gcleaner", "None", "GCleaner", "2024-04-23 16:46:16", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:36", "1260782", "388f8e4c20dc864b76be96bd03826fb8a429954c4a5e8d1f947d9f7c16b0276a", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "2024-04-23 16:46:12", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:33", "1260779", "4d8b8c49b376c483e08d172646b49baf697d54b815b8357008117fed39c92cb0", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:46:10", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:30", "1260776", "37fed616ca62e00a6a8b6dfc9d6c52107761e76916617f5b989c85410ebbceee", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:46:07", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:28", "1260773", "d644e92ab06e7ff19e5f10453d102137a2d057a0a97e6890cec905a211c7f467", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:46:04", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:25", "1260770", "aa3fdf09f5e73e4a23580d387717148203f6c2d365ab64caffc109fcc7856ff5", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:46:01", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:22", "1260767", "02f1e7955a182f8488b636ec84999bf14b186905e84e3dc796a8eeb1dc84177f", "sha256_hash", "payload", "win.xworm", "None", "XWorm", "2024-04-23 16:45:58", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:19", "1260764", "cebfc262ed776fc235c66ac28d9d508049fa15cfac213a6fc15bb339ff2010a8", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:45:55", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:16", "1260761", "d8709578715146d9c0b71368582ab890823bd727e47a9ef2af671507a113835a", "sha256_hash", "payload", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "2024-04-23 16:45:52", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:13", "1260758", "8059b091c68e00ab352c556470e048a620e05cf3dd09d9abea91046483c237d0", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:45:48", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:10", "1260755", "ea7ce7b027037dcdf996ccc19ae94a98c1eca5acc4845590b7f907e99431ccb3", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:45:44", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:07", "1260752", "1e780a37c1c123cb74d959cfc1cac010bab7e56805d9afeb394bc2b1c4132e3a", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:45:41", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:04", "1260749", "3fce144519b73bde4b30740ced6678a0aebcfcf00c7ff2ed6f78034cd5900f56", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:45:38", "95", "None", "None", "0", "Grim" "2024-04-23 16:08:01", "1260746", "ecc9bbdafb2ba01909619fcb94b8cd7ea04eed985362af023e18f90f7e989a96", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:45:35", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:58", "1260743", "438880c0c81de087ba1fc1192002342f4aa8ee080af2c85e83a548ef774990d6", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:45:31", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:55", "1260740", "0ef2b9d87399cd369deb211f239696ad618c5e4c51888fb31d2c573e1d8b8e53", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:45:27", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:51", "1260737", "a3f5e3e9e01fdd51293410aa65759c2ea0ba6fd96860b6b9e9e0cea139f4d939", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:45:21", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:48", "1260734", "301a02cc0eb727a274bb807cb64022861b228129709070739721c9a4548918ea", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:45:10", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:45", "1260731", "92d6b2ccfc3f6f350b4c5f989022abda28a982e9fe0bb4121ad4092802e1a758", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:44:58", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:42", "1260728", "cc4eb6b1d8a54f9ad9c8483ba7ac4a141db452a40299719090ff7b1878047063", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:44:53", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:39", "1260725", "d1b0b9a6b80f54be2a14ff19f3bd682185848d92443fa555a08cb07fa630a230", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:44:48", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:36", "1260722", "00bb8cbb9383dc5c8465ad73cded278f4b9407cd66c209c529575f047480efbe", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:44:42", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:33", "1260719", "acc31b4538f0c0f8e16d30262762f5d8695fe6b18d9b3294f2176b0b960bbe09", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:44:39", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:30", "1260716", "635d1ea9728310e492a728ff14145c39a5c7594ebd75b9c70e4d44d45f9bd85b", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:44:35", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:27", "1260713", "c1d0339f73af46c63b7ab866c65a1cdc636cfdb12492587cee7bb92486a917f0", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:44:32", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:24", "1260710", "a464f8ca48e3193c3c58bec992d90875712d87a0165c24568e0b09c700364154", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:44:28", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:21", "1260707", "3581c582d74f219116323f1c9b14cfdfecf07d07b604b2a2670af6d6a849f99f", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:44:25", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:18", "1260704", "75161e2443246e9e3bf1e11921abc074b612417e8ad06e6f937ac0973fca3e92", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:44:22", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:15", "1260701", "1e9f56f3709d1ecef0ebd00e173acf65f93d84439647a193ae558728dddff327", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:44:19", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:12", "1260698", "b94bd24023b0df0089295b2246546a256d3e82424ecdb0c596b3500525aa4de0", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:44:16", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:08", "1260695", "517a4c4d84de92e88d51de7f864fbdff01b5b2a3e6e0930a291ada3787af9441", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:44:12", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:05", "1260692", "92afa7a9c3f0dceaaba64f46bee7623f43c94fa04dc56c8704f9f82f2054e453", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "2024-04-23 16:44:09", "95", "None", "None", "0", "Grim" "2024-04-23 16:07:02", "1260689", "4cf20ea54fb348cc2573628cf6d751faa35d3adf5317970068d28185c5a285c9", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:44:06", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:58", "1260686", "50c1f47ff04f921e35bea4149cc4737fc03288988c78d5b878e384a3414bd707", "sha256_hash", "payload", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "2024-04-23 16:44:02", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:55", "1260683", "f48bc5d53964eaabd32c0dd7a11403b8b259c86331a37bf73b54e47ad6b101f1", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:43:58", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:52", "1260680", "cb664fc08a69a03e1d7ad2d47b9d7397330601fcfd8d559149ee606d782f14ad", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:55", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:49", "1260677", "6c67d74401297f52a8e42e2f00b315147bd77913209189a483dbf09fea7e7b4a", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:52", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:46", "1260674", "56a64e0330950bad93c69d12a297d66f8df92e46fcc2cf4fc5e645579ecca632", "sha256_hash", "payload", "win.lpeclient", "LPEClientTea", "LPEClient", "2024-04-23 16:43:49", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:43", "1260671", "98429340d6bc2f1dae7f048fdbf1ce802b524934c0a61945545d450a1df6d751", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:45", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:39", "1260668", "8364130d6b98b51842ee9213647616bf8126c8506c0721947f6f17a83f600c6d", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:42", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:36", "1260665", "5cb642e33d49c06da371af485c11bf2220fa4bb6a47eac607fa9dfad36c90d60", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:38", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:33", "1260662", "f0f1b858d0010a822374ab8381f6bf6be7c8ff88bab30b5cdf89e72f93062d51", "sha256_hash", "payload", "win.coinminer", "None", "Coinminer", "2024-04-23 16:43:35", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:30", "1260659", "dadc6e78d7628c9b004c60834d4f20729bf6718b972c31ef08c3bb7181a39a7f", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:32", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:27", "1260656", "927abb8fad22ff1ce9ee93c8ab9cb8370c9b2e445a994a3902245d91a9d6c24b", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:28", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:24", "1260653", "ca097627fe7a4ed8060c03c3ecd3ad8cb79454cdb114d79f061bb52a27dec260", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:25", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:21", "1260650", "33be117742dab9ec99708bb15889fcf6434d29525c750c4dbca9635d046d92e2", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:22", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:18", "1260647", "2b7efff0b80e8a25e6acba7d686ba3836d3d672d62b880e3661587658edeee40", "sha256_hash", "payload", "win.stealc", "None", "Stealc", "2024-04-23 16:43:19", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:14", "1260644", "c7cd9c0bfb7ad72cc4270690f8bb73535357e89845749ce19233d8d7d64cd47d", "sha256_hash", "payload", "win.vidar", "None", "Vidar", "2024-04-23 16:43:15", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:11", "1260641", "f69561433962f52a78eb8a5d4c8a1d7ad19e80130f8cb2eed05dc2a5596b3cfb", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:43:12", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:08", "1260638", "5c08922622153fcfa1cf05af7f0bdf474c6f9990c4f529742516a03362675cc0", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:43:08", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:05", "1260635", "047315e937d8697bccc03e03215f5a43ac3c1cde7c4e18dc9d1e55b14af01293", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:43:01", "95", "None", "None", "0", "Grim" "2024-04-23 16:06:02", "1260632", "2be6d4af94bd90a37e68ced92b6dc0bde062b51f7f22e1323f2c361b7f4d1e15", "sha256_hash", "payload", "win.gcleaner", "None", "GCleaner", "2024-04-23 16:42:57", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:58", "1260629", "0b51f3120c7d31f504bd67b8bc8e9f41ca580b77bbf3a2aaa257bb1232d31073", "sha256_hash", "payload", "win.lpeclient", "LPEClientTea", "LPEClient", "2024-04-23 16:42:52", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:55", "1260626", "205cac67754c6dd6a1c8945b76c800a5019eef9c66d0dde1519ea6c4c1e70976", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:42:48", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:52", "1260623", "ae300b28b2240d11d01e9066a26a88349258d4016c41460604c9ff5bb64c9b6d", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:42:43", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:49", "1260620", "c9495cc11ac18b285ddfe9c82c76d789a5caa7179f7500cc5e6ec7d659ca8c54", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:42:39", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:46", "1260617", "3ca71ea7d01b1f1e3613781fcd68b47c09a159af5876c134065bef4d912917a6", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:42:34", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:43", "1260614", "a22b502cc5b1476fef59963f2df2eaea9086e775923d82308cecac83d5c5cbcd", "sha256_hash", "payload", "win.strelastealer", "None", "StrelaStealer", "2024-04-23 16:42:30", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:40", "1260611", "01ef75f76ae452476b1de15a3238617f33c4b685e5bb423de49f34f44b0a0111", "sha256_hash", "payload", "win.dcrat", "DarkCrystal RAT", "DCRat", "2024-04-23 16:42:26", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:37", "1260608", "331ca91b3a643aab796547bdd69ecd624ab13ac224ea80f88ca4a8987c0625e3", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:42:21", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:34", "1260605", "61e2a9db8f357380b18ba1017f2ae52d656d2c5f4de8851e244566b8c986d88a", "sha256_hash", "payload", "win.formbook", "win.xloader", "Formbook", "2024-04-23 16:42:17", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:31", "1260602", "6c06c665c435cf95787310f59e984006711d50bf091ae610cb4440abae1448c4", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:42:12", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:28", "1260599", "b06755606adaa10b7b75bc045bbaa13dcfbcd6c79a4b85f4914abbd92fbf8b21", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:42:07", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:25", "1260596", "f8dccc6cb76c461ef6d1623050e3d3121acaa5d0467fb013c44fa422d4d65806", "sha256_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "2024-04-23 16:42:03", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:20", "1260593", "1254ede011ea7c8ba1658bab1c14877d1a2dc85f8b4e2d04be6c5fc65f1c32b8", "sha256_hash", "payload", "win.strelastealer", "None", "StrelaStealer", "2024-04-23 16:41:58", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:15", "1260590", "7c5b92ed56a0a571be9ebe0e12e887b1a0b545ed615268e9b783558fd06dc098", "sha256_hash", "payload", "win.quasar_rat", "CinaRAT,QuasarRAT,Yggdrasil", "Quasar RAT", "2024-04-23 16:41:55", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:10", "1260587", "9aba50dd48714364d76d490813efafdf754268b2cea3edd571bf4abe5704c8c8", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:41:51", "95", "None", "None", "0", "Grim" "2024-04-23 16:05:05", "1260584", "d3b6e366a802b7cd639108f9d4b36588736bcc77a32ee9796ad42ec294af2e46", "sha256_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "2024-04-23 16:41:48", "95", "None", "None", "0", "Grim" "2024-04-23 16:04:59", "1260581", "97d983df8e02cb6f1ed5d21cf776d071daee77081d83fde4721ac96fc168bbb3", "sha256_hash", "payload", "win.dcrat", "DarkCrystal RAT", "DCRat", "2024-04-23 16:41:44", "95", "None", "None", "0", "Grim" # Number of entries: 152