top title background image

Malware Analysis Reports

Latest behavior analysis reports generated by Joe Sandbox and Joe Reverser

Joe Reverser 1.3.0
10/04/2026

Analysis Report
HWMonitor supply chain attack installing Cobalt Strike

a259c68a679e5842303f469275c9f750d7c1d7b58aa08e7dbec2e1d4c3dd01ce
Joe Reverser 1.3.0
09/04/2026

Analysis Report
A custom 64-bit Windows post-exploitation tool designed to bypass Defender, dump SAM credential hashes, and escalate privileges using a multi-stage attack chain. It leverages oplock-based TOCTOU attacks, offline SAM decryption with syskey, and Defender RPC abuse, with low AV detection and no known malware family or C2 infrastructure.

SHA256: 93008c42764b74b759678fd376abd90696f74af408600727b6649286d8424270
Joe Reverser 1.3.0
08/04/2026

Analysis Report
A phishing email impersonates a trusted sender and uses a redirect chain to deliver a fake Microsoft sign-in page for credential harvesting. It leverages an AiTM phishing kit, legitimate platforms, and CAPTCHA evasion to bypass detection.

SHA256: 1397f2f3bcf96ceac38e00b3c341e72fcc4cf1829638818cfd5182457e77ca35
Joe Reverser 1.0.0
17/02/2026

Analysis Report
Multi-stage decryption from URL to dropper to payload (Vidar)

hxxp://206[.]0xF5[.]132[.]218/RTENijPkBl[.]odd
Joe Reverser 1.0.0
11/02/2026

Analysis Report
Beautiful ClickFix deploying RAT via Dll hijacking

hxxps://google-securedocs[.]makeneg458[.]workers[.]dev/?id=l69l06y0
Joe Reverser 0.9.0 (Beta)
14/01/2026

Analysis Report
LLM Bot using GenAI to generate malicious code

SHA256: 92ef24201c32053bce7d663e53795d5fb4b5c26af951519d87f7e11a6a8ce494
Joe Reverser 0.9.0 (Beta)
13/01/2026

Analysis Report
Reversing of VoidLink Stage 1

SHA256: 13025f83ee515b299632d267f94b37c71115b22447a0425ac7baed4bf60b95cd
Joe Reverser 0.9.0 (Beta)
13/01/2026

Analysis Report
Reversing of VoidLink Stage 0

SHA256: 70aa5b3516d331e9d1876f3b8994fc8c18e2b1b9f15096e6c790de8cdadb3fc9
Joe Reverser 0.9.0 (Beta)
13/01/2026

Analysis Report
Deep Analysis of VoidLink Implants

SHA256: 05eac3663d47a29da0d32f67e10d161f831138e10958dcd88b9dc97038948f69
Joe Reverser 0.9.0 (Beta)
29/12/2025

Analysis Report
Docusign Phishing Analysis

Joe Reverser 0.9.0 (Beta)
16/12/2025

Analysis Report
Analysis of Sandbox evasion

SHA256: 60d2b37f8800034b099f421108360ca4b7575ad1bbb8df4767cbe34122951af3
Joe Reverser 0.9.0 (Beta)
03/12/2025

Analysis Report
Salvador Android Stealer

SHA256: 21504d3f2f3c8d8d231575ca25b4e7e0871ad36ca6bbb825bf7f12bfc3b00f5a
Joe Reverser 0.9.0 (Beta)
03/12/2025

Analysis Report
RevoltRat uses Revolt for C2 communication

SHA256: 8309a091cb7b8cdf496b696c7c0dd407e8c90bc1e9735c6845c9dc675506c5b3
Joe Reverser 0.9.0 (Beta)
1/12/2025

Analysis Report
Full reversing of MasonRAT V6 CPL incl. unpacking

SHA256: 6878354bb55ddb58cb56cd26aaa07c60fc61b275b9cd53a5e87d08c5def0d0ae
Joe Reverser 0.9.0 (Beta)
28/11/2025

Analysis Report
GrokPy uses Grok LLM model to solve CAPTCHAs

SHA256: 239d6bd4b8e29a34d68e078c85a008e5e0a0fa02ae6c12cd33ecf0ed80e79680
Cloud 42.3.0
17/10/2025

Analysis Report
Rhadamanthys delivered by an in-browser fake Windows Update, abusing the Fullscreen API (on-click), and using ClickFix-style

hxxps://thefatshallot[.]com/
Cloud 42.0.0
21/05/2025

Analysis Report
CloudFlare Theme ClickFix/CAPTCHAScam dropping Redline

hxxp://gogocharters[.]com/lexington-charter-bus
Cloud 42.0.0
13/05/2025

Analysis Report
Phishing Chain from e-Mail to Catpcha to Tycoon2FA

SHA256: c99ce182e582b618ae2fe4c7258fc113625730739086e73029f022fb689588b4
Cloud 41.0.0
31/10/2024

Analysis Report
CloudFlare Theme ClickFix/CAPTCHAScam dropping NetSupport RAT

hxxps://webdemo[.]biz
Cloud 40.0.0
09/07/2024

Analysis Report
EvilProxy using open redirect vulnerability

https://m.exactag.com/ai.aspx?tc=d9282403bc40b07205bbd26a23a8d2e6b6b4f9&url=http%3Asellartatauction.com/oplo/osiwuhjfmniek/bobibobi@outlook.com
Cloud 40.0.0
10/05/2024

Analysis Report
HTML payload leading to download and installation of WSHRAT

SHA256: 427fb9938ca75db1a362fe51356a1dc06350daa5f9db788a4ca2f7e2cb21fd34
Cloud 40.0.0
07/05/2024

Analysis Report
HTML based phisher exhibiting a large spectrum of malicious behaviors

SHA256: 360a04ca0c6ef3401d14f04089d6e7e08869ab298dbf842d8f063bfaca618891
Cloud 38.0.0
12/07/2023

Analysis Report
CVE-2023-36884 using RTF to load Word DOC via MSHTML iframe injection

SHA256: a61b2eafcf39715031357df6b01e85e0d1ea2e8ee1dfec241b114e18f7a1163f
Cloud 38.0.0
15/06/2023

Analysis Report
SolarMarker with file pumping, valid PE signature, Powershell dropper and .Net backdoor

SHA256: 6f7332625d573ccc7b14264ee0db7e671305e1206c7eaf920e17c26f7b5b64a7
Cloud 37.0.0
15/02/2023

Analysis Report
STOP Djvu Ransomware via SmokeLoader with full config extracted

SHA256: 5ea4451ca1ce36db2dc6e7a85f07c748ddbb758b65f2194d734afd08bd141126
Cloud 36.0.0
15/09/2022

Analysis Report
AgentTesla v3 with full malware configuration

SHA256: c6dae959f8e5373c6ac8746cfd8227b8d8099b692ee726aacbe18ecf1479282e
Cloud 35.0.0
26/07/2022

Analysis Report
Stealthy new payload delivery method: HTML (showing a PW) -> ZIP encrypted -> ISO -> LNK -> Calc.exe -> DLL -> DLL -> QBOT

SHA256: f5c16248418a4f1fd8dff438b26b8da7f587b77db9e180a82493bae140893687
Cloud 33.0.0
01/02/2022

Analysis Report
noPac using CVE-2021-42287 - CVE-2021-42278 Exploit to gain DC Admin

SHA256: 4e37819484e865f8e20c2aaa94ec05f3bfe3bb6f36ea4bb6df376c8d4f1ffcca
Cloud 33.0.0
12/01/2022

Analysis Report
SysJoker Multi-Platform Backdoor

SHA256: 1ffd6559d21470c40dcf9236da51e5823d7ad58c93502279871c3fe7718c901c
Cloud 33.0.0
23/12/2021

Analysis Report
Emotet dropped by Hidden Macro

SHA256: bb1f500a59544aa8e44a0377cc506dfbebca1ecb7a8c73dc72d3268803976ff5
Cloud 33.0.0
25/08/2021

Analysis Report
Kimsuky Espionage Campaign, JS instrumentation

SHA256: 20eff877aeff0afaa8a5d29fe272bdd61e49779b9e308c4a202ad868a901a5cd
Cloud 33.0.0
22/07/2021

Analysis Report
Hanictor analysis with VBA and shellcode execution graph, dropping FickerStealer

SHA256: 83c9c9beaca0a147e23995b84792f56cd130ccf262147374bd1114c2ac698fee
Cloud 33.0.0
15/07/2021

Analysis Report
Kaseya attack dropping Sodinokibi

939aae3cc456de8964cb182c75a5f8cc
Cloud 44.0.0
14/01/2026

Analysis Report
Digit Stealer (AppleScript-based Info Stealer Payload) on Sequoia (ARM64)

SHA256: 5d8a374139573798e23de60d1ca1610f6d1abecd5d17ecf32c82f1cfd338e03f
Cloud 41.0.0
26/08/2024

Analysis Report
Cthulhu Stealer on Ventura (ARM64)

SHA256: 6483094f7784c424891644a85d5535688c8969666e16a194d397dc66779b0b12
Cloud 37.0.0
23/08/2023

Analysis Report
XLoader (Objective-C) on Ventura (ARM64)

SHA256: 453e155722ac23771d63418e39f88430b0a922bd5f4afa81dcc73db44571b79e
Cloud 37.0.0
16/08/2023

Analysis Report
LockBit randomware analyzed on native MacMini Apple Silicon (ARM64) with macOS Ventura

SHA256: 3e4bbd21756ae30c24ff7d6942656be024139f8180b7bddd4e5c62a9dfbd8c79
Cloud 35.0.0
24/08/2022

Analysis Report
XCSSET trojan

SHA256: 483b2f45a06516439b1dbfedda52f135a4ccdeafd91192e64250305644e5ff48
Cloud 35.0.0
18/08/2022

Analysis Report
NukeSped with Coinbase PDF (Lazarus)

SHA256: fe336a032b564eef07afb2f8a478b0e0a37d9a1a6c4c1e7cd01e404cc5dd2853
Cloud 34.0.0
04/05/2022

Analysis Report
NukeSped.N with Decoy PDF (Lazarus)

SHA256: 55571ac52e1f02f18af77e2f3314382c982a37744b58732dfc15faac9d66619f
Cloud 34.0.0
28/03/2022

Analysis Report
Gimmick Trojan

SHA256: 2a9296ac999e78f6c0bee8aca8bfa4d4638aa30d9c8ccc65124b1cbfc9caab5f
Cloud 33.0.0
26/01/2022

Analysis Report
DazzlySpy Trojan implant

SHA256: f9ad42a9bd9ade188e997845cae1b0587bf496a35c3bffacd20fefe07860a348
Cloud 33.0.0
12/01/2022

Analysis Report
SysJoker Multi-Platform Backdoor

SHA256: 1a9a5c797777f37463b44de2b49a7f95abca786db3977dcdac0f79da739c08ac
Cloud 33.0.0
12/11/2021

Analysis Report
MACMA aka CDDS Payload used in watering hole attack campaign

SHA256: cf5edcff4053e29cb236d3ed1fe06ca93ae6f64f26e25117d68ee130b9bc60c8
Cloud 32.0.0
15/09/2021

Analysis Report
OSX ZuRu running in trojanized iTerm2

SHA256: e5126f74d430ff075d6f7edcae0c95b81a5e389bf47e4c742618a042f378a3fa
Cloud 33.0.0
22/07/2021

Analysis Report
XLoader / Formbook info stealer on macOS

SHA256: 81c4276f2e3c0ed456b08402a6a5b63d0cad68220b7a3275b3cbf0ba73faaa21
Cloud 32.0.0
09/07/2021

Analysis Report
WildPressure macOS Python (analyzed with Live Interaction)

SHA256: 1448f34fcde1e6d7df000c38a61c3dd6d5fd304f9ad60cadfa3deb875b6b088f
Cloud 31.0.0
28/04/2021

Analysis Report
Shlayer with CVE-2021-30657 exploit for bypassing Gatekeeper, File Quarantine and Application Notarization

SHA256: 70c6f9da05046525605e2066185929c2659e27a3851dc43d8aa69e2692e6154f
Cloud 40.0.0
10/04/2024

Analysis Report
Dinodas RAT on Ubuntu 22.04 x64

SHA256: 15412d1a6b7f79fad45bcd32cf82f9d651d9ccca082f98a0cca3ad5335284e45
Cloud 35.0.0
21/07/2022

Analysis Report
TeamTNT variant mining Raptoreum (RTM) cryptocurrency

SHA256: 4f4fef3aa02d725b00793b75afcd2d75ecd554a9a23cb3e7d87969b3226f72b1
Cloud 33.0.0
12/01/2022

Analysis Report
SysJoker Multi-Platform Backdoor

SHA256: bd0141e88a0d56b508bc52db4dab68a49b6027a486e4d9514ec0db006fe71eed
Cloud 33.0.0
30/11/2021

Analysis Report
Abcbot botnet malware

SHA256: 22b521f8d605635e1082f3f33a993979c37470fe2980956064aa4917ea1b28d5
Cloud 32.0.0
06/08/2021

Analysis Report
XMrig cryptominer disabling HW prefetcher in MSR registers

SHA256: 28e9b06e5a4606c9d806092a8ad78ce2ea7aa1077a08bcf3ec1d8e3d19714f08
Cloud 32.0.0
01/07/2021

Analysis Report
REvil Linux (analyzed with Live Interaction)

SHA256: ea1872b2835128e3cb49a0bc27e4727ca33c4e6eba1e80422db19b505f965bc4
Cloud 38.0.0
28/09/2023

Analysis Report
Xenomorph, targeting over 30 different banks

SHA256: 259e88f593a3df5cf14924eec084d904877953c4a78ed4a2bc9660a2eaabb20b
Cloud 38.0.0
28/06/2023

Analysis Report
DexPro protected APK using multiple Android Zipfile parser flaws

SHA256: b3561bf581721c84fd92501e2d0886b284e8fa8e7dc193e41ab300a063dfe5f3
Cloud 35.0.0
18/08/2022

Analysis Report
S.O.V.A analysis on Android 12 Snow Cone

SHA256: b01b74aaf249d0740f541c081c0c0de4bf455b4b68f2634fab6cf8aafcd95d52
Cloud 33.0.0
10/09/2021

Analysis Report
S.O.V.A. Banking Trojan

SHA256: efb92fb17348eb10ba3a93ab004422c30bcf8ae72f302872e9ef3263c47133a7
Cloud 33.0.0
29/07/2021

Analysis Report
TEABot e-Banking trojan

SHA256: 89e5746d0903777ef68582733c777b9ee53c42dc4d64187398e1131cccfc0599
Cloud 40.0.0
10/04/2024

Analysis Report
Dinodas RAT on Ubuntu 22.04 x64

SHA256: 15412d1a6b7f79fad45bcd32cf82f9d651d9ccca082f98a0cca3ad5335284e45
Cloud 35.0.0
21/07/2022

Analysis Report
TeamTNT variant mining Raptoreum (RTM) cryptocurrency

SHA256: 4f4fef3aa02d725b00793b75afcd2d75ecd554a9a23cb3e7d87969b3226f72b1
Cloud 33.0.0
12/01/2022

Analysis Report
SysJoker Multi-Platform Backdoor

SHA256: bd0141e88a0d56b508bc52db4dab68a49b6027a486e4d9514ec0db006fe71eed
Cloud 33.0.0
30/11/2021

Analysis Report
Abcbot botnet malware

SHA256: 22b521f8d605635e1082f3f33a993979c37470fe2980956064aa4917ea1b28d5
Cloud 32.0.0
06/08/2021

Analysis Report
XMrig cryptominer disabling HW prefetcher in MSR registers

SHA256: 28e9b06e5a4606c9d806092a8ad78ce2ea7aa1077a08bcf3ec1d8e3d19714f08
Cloud 32.0.0
01/07/2021

Analysis Report
REvil Linux (analyzed with Live Interaction)

SHA256: ea1872b2835128e3cb49a0bc27e4727ca33c4e6eba1e80422db19b505f965bc4
Cloud 34.0.0
09/05/2022

Analysis Report
Bumblebee Loader with extensive Anti-VM and Anti-Sandbox techniques

SHA256: c65c51ed60f91a92789c4b056821ef51252baa2a1679a6513ab008acf0464ccb
Cloud 28.0.0
24/01/2022

Analysis Report
Date-aware (<20.1.2020) Cassandra Crypter dropping AgentTesla

MD5: a24c195da4f8a5dee365875b3e3a38a1
Cloud 28.0.0
22/01/2022

Analysis Report
TrickBot Downloader counting total number of processes

MD5: 3e8c58262860fcbce68af93f4a022232
Cloud 33.0.0
14/10/2021

Analysis Report
Evasive GuLoader dropping Formbook, bare metal analysis

ab5135e71815ad27daf57be78754c85d
Cloud 40.0.0
10/07/2024

Analysis Report
Greatness phisher with full config extractor

https://materialesvite.com.mx/upload/QebqNQebqN/QebqN/YWxiZXJ0by5kb3Npb0B0aGFsZXNhbGVuaWFzcGFjZS5jb20=
37.1.0 Beryl
26/06/2023

Analysis Report
Strela Stealer

SHA256: 14009b05324320da1f4942c35d0cfd24b5dbc49773ce4618e6e070d74a7ffb6a
37.1.0 Beryl
25/06/2023

Analysis Report
Redline Clipper

SHA256: 9802c511f650d5eb611d309889655ac2f8daab5f87c30463b2505da99076192b
37.1.0 Beryl
08/06/2023

Analysis Report
Kraken Rat

SHA256: 0eef67dbee8912b9267f7ca7f7eb4f63547bc8d336bdddc22f98c14563c32515
37.1.0 Beryl
22/05/2023

Analysis Report
Typhon Logger

SHA256: bebd7434928eb7d1fb89a84ba41c3838fb5734f446b58b8bfb2d5dddf48e518b
37.0.0 Beryl
04/04/2023

Analysis Report
Stealerium

SHA256: 86aa79c05ad10f311c2c4d97ddc40d8fb048d25271d68387608aff6600bb5ac4
37.0.0 Beryl
22/03/2023

Analysis Report
RHADAMANTHYS

SHA256: 9e068da322450ae34e33254c3bd919c1a38c5387f10f99ce4305bc63452acea6
37.0.0 Beryl
22/03/2023

Analysis Report
StealC

SHA256: b020c34a3b2b4bc4fbfa0ac4d3ca97283e2fdce71f737e1103bd638ed8f6647a
37.0.0 Beryl
22/03/2023

Analysis Report
WshRat

SHA256: 5f0329e51f347ca573ea69cd865bb03d0526d9e9e91477a4502a9fe35c3fbddf
37.0.0 Beryl
21/03/2023

Analysis Report
Vector Stealer

SHA256: 86e233cb75b893c9e4e0d26385155c4f575e4217f2d52cba592641c996bc9cc8
37.0.0 Beryl
17/03/2023

Analysis Report
Aurora

SHA256: 5892a93d287a1e4bd97fb09b79b6e2af5643103511f3678c8212ec803ff3b449
37.0.0 Beryl
16/03/2023

Analysis Report
Chaos

SHA256: 074c7aa722ff77df5ed56b655cc11da0288550a7405dc439be4417c6fccf7d5f
37.0.0 Beryl
16/03/2023

Analysis Report
Kovter

SHA256: a597d34bc2464c3ace48ac04f6653f65ac4822ea8e4a5717ba9e4909b8c62240
37.0.0 Beryl
08/03/2023

Analysis Report
Luca Stealer

SHA256: 70805738871f24f390c7b1e62e6b48bc4850399992d8b62bba3160550a0a3655
37.0.0 Beryl
02/03/2023

Analysis Report
Qbot Downloader

SHA256: 56734da861a7d95f690e0172e717cc933513e37677c18c9277a2a261e55090ac
37.0.0 Beryl
27/02/2023

Analysis Report
VenomRat

SHA256: 35330f1bbbc0f361845b9b987e2f4ac70cdb96ab3f9e80161c2b8971c7df0df4
36.0.0 Rainbow Opal
17/02/2023

Analysis Report
Upatre

SHA256: 215c37360388d16653ffc1740c639d486753a9db69a8ad4f3e1b172b1b712df4
36.0.0 Rainbow Opal
14/02/2023

Analysis Report
JCrypt

SHA256: 8bf1319fd0f77cd38f85d436e044f2d9e93e3f33844f20737117230b73b60f6c
36.0.0 Rainbow Opal
31/10/2022

Analysis Report
Nymaim

SHA256: c360868055519b145bf9169b913787cd1f6533995e4d8a8556f94676a6129f96
36.0.0 Rainbow Opal
31/10/2022

Analysis Report
Crimson

SHA256: ca74472613129855bd7fc79c4a245a2f27de85086cfd191506f1c9906b9ae460
36.0.0 Rainbow Opal
28/10/2022

Analysis Report
LockBit ransomware

SHA256: 367f5b45da98215ff297e0856e4a961c9e831e4f06457f16453f60d0cf407449
36.0.0 Rainbow Opal
24/10/2022

Analysis Report
Eternity Stealer

SHA256: 4cb0b838560c4e859b8aa29c40fffde2f196a827eda7f69a2b766299651c50df
36.0.0 Rainbow Opal
24/10/2022

Analysis Report
PhoenixRAT

SHA256: 77cb17ef2f4f282f39838e7430bf040c3356e59ae8f13cbd4e670712e9f44a4e
36.0.0 Rainbow Opal
23/10/2022

Analysis Report
Erbium Stealer

SHA256: b8490732ccb34fdd76910ee15aa3eced95ef445f2ab287d45181f98f44742df1
36.0.0 Rainbow Opal
18/10/2022

Analysis Report
CryptbotV2

SHA256: 29842f71bd503e86896ae4b274aa21a0eaa67144ad83e2df89072ea8e8458fd0
36.0.0 Rainbow Opal
15/10/2022

Analysis Report
Vermin Keylogger

SHA256: af1d446bb3abc47b5eacb7a00ebb1992be1c464cac5b0e4283b12f0500c3ad4e
36.0.0 Rainbow Opal
10/10/2022

Analysis Report
S500Rat

SHA256: b3f2810e4ba5c3341498d99807e2f200459eb2bd4d365b3ee52a20e9e12606c1
36.0.0 Rainbow Opal
06/10/2022

Analysis Report
LummaC Stealer

SHA256: f33a6585faa522f1f03b4bacbd77cb5adc0d1ad54223b89dc8f6ebb05edfe000
36.0.0 Rainbow Opal
21/09/2022

Analysis Report
Kutaki

SHA256: de09ae47bc867cc2d931c49a3b77cb6107f48e8c00c38a7c3e57b85db8a80452
36.0.0 Rainbow Opal
31/08/2022

Analysis Report
Phorpiex

SHA256: a8d0ac5762f61683d7cbcbfc53e0b650e632625d7ffabf08b45986908891ee96
35.0.0 Citrine
22/07/2022

Analysis Report
Eternity Clipper

SHA256: a23855393505a14023834569b263ceebd810a4f041716b4f606f5ba9d25c265a
35.0.0 Citrine
08/07/2022

Analysis Report
Rook

SHA256: c2d46d256b8f9490c9599eea11ecef19fde7d4fdd2dea93604cee3cea8e172ac
35.0.0 Citrine
08/07/2022

Analysis Report
BumbleBee

SHA256: e6c6ad0411501c2d81863c0ecaf80ace8a5e9b6ce8329c5700890eb36991f6fb
35.0.0 Citrine
08/07/2022

Analysis Report
BlueBot

SHA256: b4851333efaf399889456f78eac0fd532e9d8791b23a86a19402c1164aed20de
35.0.0 Citrine
08/07/2022

Analysis Report
Predator

SHA256: d9536057855ddfa0656463b11191f1fd1a34f95032c676f7d3afc7cd5372068b
35.0.0 Citrine
07/07/2022

Analysis Report
Tofsee

SHA256: a96edd53cb70eb51f8bb9fbd0b9d0777e6b65c5203fb3b73229431b49da155e4
35.0.0 Citrine
07/07/2022

Analysis Report
BluStealer

SHA256: 6e7ed6e2800cb45547906279f027fe098d08bb0dbc517ce41fe0ebe33222ab99
35.0.0 Citrine
30/06/2022

Analysis Report
Socelars

SHA256: 07a029536d442a18485d88a48362cd84a184a6e54695496b1462b7f6d9a2c2c1
35.0.0 Citrine
24/06/2022

Analysis Report
Xtreme RAT

SHA256: 484310027c8e469f5154e53c9d3543095410b68730722158848b01d5a842642c
34.0.0 Boulder Opal
17/03/2022

Analysis Report
Matanbuchus

SHA256: 490bcee7c0b9607d834fd8b3e5d01613d062fcf48be043e6f5f60c5077b55e3c
34.0.0 Boulder Opal
03/03/2022

Analysis Report
Allcome clipbanker

SHA256: 6ccf16f1d1a495de9f5e7c1b60dd09da612ba2355887ebeb56cc1cacb5d64a5e
34.0.0 Boulder Opal
16/12/2021

Analysis Report
Jester Stealer

SHA256: 2f60704e2dac47d532955485a04c195dffa41f9e638527ac42c82a224b2202ea
33.0.0 White Diamond
24/10/2021

Analysis Report
BlackMatter

SHA256: 22d7d67c3af10b1a37f277ebabe2d1eb4fd25afbd6437d4377400e148bcc08d6
Cloud 33.0.0
14/10/2021

Analysis Report
DanaBot

SHA256: 18ae9ea1c1d71b33777c8772248580f17a2bcecf1aa0e8f71ec15d4b33d5253b
Cloud 33.0.0
14/10/2021

Analysis Report
AveMaria

SHA256: 7eb784edddde0eddd7b21c4907916f0109334a4237a9c2eb917caf8eae81480f
Cloud 33.0.0
13/10/2021

Analysis Report
Cryptbot Glupteba

SHA256: 84f4e2b346b6f5473e2c564a6f60985c5d20f621e70a982e9aafd21354ccc66f
Cloud 33.0.0
13/10/2021

Analysis Report
BitRat

SHA256: 881003326302ab243f71138e2e39517677c9117fd73e50f8989ee9b39e86407b
Cloud 33.0.0
12/10/2021

Analysis Report
Oski

SHA256: dda5d47308c0ebcb2555cda19b4c05a88d633396909456b9ee5fcee42e197724
Cloud 33.0.0
12/10/2021

Analysis Report
Matiex

SHA256: 6e039c725ce804c6aae1d4d56d11802a125895bf71bf99e293ec333b91cbc73b
Cloud 33.0.0
08/10/2021

Analysis Report
Fareit Pony

SHA256: 2cec15c8fef9435abd5c332486d8ad7083eeb9eb84de9077b5bf6bb42458dba5
Cloud 33.0.0
08/10/2021

Analysis Report
Clipboard Hijacker

SHA256: 5bc09c3c2a751169a32cf97a62765f127bce2d0eadce3481a6a831b6fdcc044e
Cloud 33.0.0
06/10/2021

Analysis Report
CobaltStrike

SHA256: fc6401d5a9a05017e8551916ac6a39894467301d3d0349f719bb11ba1ecc38d6
Cloud 33.0.0
04/10/2021

Analysis Report
Djvu

SHA256: 0d977e55742460c71884d6040178fc8c7abf8c97136b6293da37cbf9c59b6778
Cloud 33.0.0
04/10/2021

Analysis Report
Squirrelwaffle

SHA256: da031faf0a918be7bf90705dac2ce63cfda65226360202ac1d53a6849592e9b3
Cloud 33.0.0
04/10/2021

Analysis Report
Jupyter

SHA256: 5cf24553e521de102628e1ebdadb69a6623904f08b51cf5b1ea14779e03e8682
Cloud 33.0.0
30/09/2021

Analysis Report
RevengeRAT

SHA256: b943704744a23c06174a36aa0e24ecc7ac67aad9edc9c4bd46dd1f007514796d
Cloud 33.0.0
30/09/2021

Analysis Report
njRat Xtreme RAT

SHA256: f32fb1af5db650065e6e1d02ade5506e6c0903e4bbc9ff6ff2fbf94bef6ffba4
Cloud 33.0.0
28/09/2021

Analysis Report
SystemBC

SHA256: c27741b9e50da0c369b848179c9a4f9b0362b6d5e384055c6c72fc9667a270ec
Cloud 33.0.0
22/09/2021

Analysis Report
Phantom Miner

SHA256: d83d1ebc7cffb2050517fe68343b2a4cb4e7ed7f45aa2c14a2dff25a8eeb9c8b
Cloud 33.0.0
15/09/2021

Analysis Report
Orcus

SHA256: 3ffef680021c116955e889822e935c55b05576f9a0f9bd1dde334c0ccbfca006
Cloud 33.0.0
07/09/2021

Analysis Report
Grandsteal

SHA256: dda8e5e4b93708ef5042d3e46027670a9ffa93f4c18646d0e48b13f8d1b013fe
Cloud 33.0.0
03/09/2021

Analysis Report
MercurialGrabber

SHA256: c2603d684ad273865985ea6e7ce27c9236e173d7633a72f2378a1309d9ec77ac
Cloud 33.0.0
25/08/2021

Analysis Report
BlackNet

SHA256: 4054ee21cbfc210489f119c2d717ca1ae43129fc0d07aefe322fabb3b61d079f
Cloud 33.0.0
17/08/2021

Analysis Report
Caliber

SHA256: cd80318bc4c724934435231e72cbf7cbf5942df8b36e480603237e2ed08d4a93
Cloud 33.0.0
27/07/2021

Analysis Report
HawkEye MailPassView

SHA256: 047f33e6f83796d9fc056d7006a6e8ef69696d63eceb29fb1592bb13a62e79bf
Cloud 33.0.0
08/06/2021

Analysis Report
FatalRAT

SHA256: 2d9002135a5b85b3f3962eab45859f1e59d20ded771b94f0e1127c6c162cb0f4
Cloud 32.0.0
29/04/2021

Analysis Report
Ursnif

SHA256: fd35940bf6701f7d98b39196b19273c86c74757ca2c226cff607fa23df183e03
Cloud 32.0.0
29/04/2021

Analysis Report
NanoCore

SHA256: c4bb3e5a6f33dca9143ede298d37b20c1dd8ab6be22f2544987f53d468e0e815
Cloud 32.0.0
29/04/2021

Analysis Report
QBot

SHA256: fff572167e03d2446c8abd0b5ddfe8657692ff07967bdd380881469df7df1484
Cloud 32.0.0
29/04/2021

Analysis Report
Remcos

SHA256: eb9e13fd092522e4dde08e96961117f9926e3ef70ca3b225f8c388e476541a21
Cloud 32.0.0
29/04/2021

Analysis Report
Formbook

SHA256: bc4765682b3b1250e178d1154cfd56fbe1fb4ac0c8e8346d9e6f3ed6c661907d
Cloud 32.0.0
29/04/2021

Analysis Report
Hancitor

SHA256: 632752c9d2297bd6b6467bd7b93f10c99716456f31e4bf314794f2ab6aeed0a8
Cloud 32.0.0
29/04/2021

Analysis Report
CryLock

SHA256: 6bc21092f49a473b0fd4d1e1a77ce5d7e97e961334764b606b7014710fb75466
Cloud 32.0.0
29/04/2021

Analysis Report
Dridex

SHA256: 53dfeaa26585a77816d74ce38b16c4b1d3db0cf346d968253eae4797db1ade10
Cloud 32.0.0
29/04/2021

Analysis Report
Lokibot

SHA256: 25b6f68e2bf505cfde67c533f5d12e869b30efe831fa82fd91c2c29f59fc77ac
Cloud 32.0.0
29/04/2021

Analysis Report
Redline

SHA256: a0faa82eeb65dec2d55e0041f18eb27652dafd93dc25e105927303e277cd8df6
Cloud 32.0.0
29/04/2021

Analysis Report
Metasploit

SHA256: 7793c2fd34248236e83206fdd01b547436e966bcb6cae21adcbf61550b62daea
Cloud 32.0.0
29/04/2021

Analysis Report
LimeRat

SHA256: a81addf8ad395ae36a617da9fb138337c17941475c1e3f3003d2571c8cb3b84e
Cloud 32.0.0
28/04/2021

Analysis Report
NetWire

SHA256: 1dcddce0408092a22c015e183e463020a7231e1f5ca47e71acad4ddcfb0f2385
Cloud 32.0.0
28/04/2021

Analysis Report
AsyncRat

SHA256: 09df870092fdf14100cf041139efcf165933d0d50c6ac8bf06fdf3116f63cfa2
Cloud 32.0.0
28/04/2021

Analysis Report
SmokeLoader

SHA256: d73e37b3ed710e4128e3c76e2f0fd61dbb2fdcddfd8cfa51ffe244fa19433bb2
Cloud 32.0.0
28/04/2021

Analysis Report
njRat

SHA256: bfd5d84c4fed8f9d23f94fe32bb7ee415dbe632c2ebaac642dbfdb73f89d0833
Cloud 32.0.0
28/04/2021

Analysis Report
TrickBot

SHA256: 7d35c3abef65ed1d81d2f70944db31ba2a8cc703f1ccf8b82ca7b3929b8233e1
Cloud 32.0.0
28/04/2021

Analysis Report
Sodinokibi

SHA256: 08c2d24cb9c632f9aa84254bb673c9df04d4ac23ee07e840794e9438b06e9bd2
Cloud 32.0.0
28/04/2021

Analysis Report
StrRat

SHA256: b63a342fa88add92fbe34e707de613c1494f08debb6ab0e4dad851b4039dc6e4
Cloud 32.0.0
28/04/2021

Analysis Report
Snake Keylogger

SHA256: b20b1c9c785100e0e18623c7f34843a82e066f0f91af93410654733c9e7e4513
Cloud 32.0.0
28/04/2021

Analysis Report
AgentTesla

SHA256: 0b10841226c0d6fb59f308c09309e79d214ca6799ac162c1addd5455d7ef3fd7
Cloud 32.0.0
28/04/2021

Analysis Report
Vidar

SHA256: 84343112791c187d10af9cea8fac68cf4fc03d72352f1fe2def0bf72f9a9afc7
Cloud 32.0.0
28/04/2021

Analysis Report
Amadey

SHA256: b5a399c0ea40983abc68b828ccb14efde2db90c047bbfba9ae418317ce7f036d
35.0.0 Citrine
24/06/2022

Analysis Report
XorDDos

SHA256: b242c3eca68edc7c09505570455398cce9b02689287690971762899d1fb2b1a8
34.0.0 Boulder Opal
23/04/2022

Analysis Report
REvil

SHA256: d42bcb0fca6d93ce4c9a78e5393f7e5949c7398ac598f7c55b76120739eac544
35.0.0 Citrine
24/06/2022

Analysis Report
XorDDos

SHA256: b242c3eca68edc7c09505570455398cce9b02689287690971762899d1fb2b1a8
34.0.0 Boulder Opal
23/04/2022

Analysis Report
REvil

SHA256: d42bcb0fca6d93ce4c9a78e5393f7e5949c7398ac598f7c55b76120739eac544