100%
Downloads and executes remote malware
linux · Index
Query analyzed artifacts from registries, marketplaces, and lab uploads — or see the latest 486 hostile catches in the fallout →
Files indexed
160,528,681+
100%
Downloads and executes remote malware
100%
Downloads and executes remote payloads
100%
Downloads and executes remote payload
99%
upx/decompression-failedpacker/upx
100%
Obfuscated Sliver C2 implant
880a9ea4c0bfcff656613559449a906f3da211c977fb8e29927b33322ccdd6dc
✓
K₃(Mc₃LiTe)O₄(CErI₃La)H₃(Cm₅F₈Ds)Md₄(ArBiBk)Th₂
100%
Xlogin/Nov24Mozilla/Oct19
b20f09da61ed52f5603e0c549a5b3880e32e4d34ccaf3f4b1628c76a939e799b
✓
K₂(Mc₃Te)O₄(ErI₃LaAs)H₃(Cm₁₃F₉Po₂)Md₄(ArBiHe)Th
100%
Mirai botnet malware
100%
delivery/downloaddelivery/fetch-exec
057d3ea58a5f5bc53d47386869544f8fd692403bc029a24db9ed26c587366b58
✓
K₃(Mc₃LiTe)O₅(CErI₃LaAs)H₂(Cm₆F₆)Md₃(ArBi₂)Th
100%
Mirai botnet malware
8c96aa076d106444fdf6cda734598cfd294d7d0cc70463e6b5aa8573a85d5ec5
✓
O₃(CP₄Er)H₆(F₅Cm₇CrDbOs₃Po₅)Md₂(ArBi₂)
100%
IoT botnet implant with C2 and persistence
202c64b8adf002065f9f272d9ee2949bc1b71411ab0f332ca3daf1d36cfbcd7e
✓
O₃(CP₄Er)H₆(F₅Cm₇CrDbOs₃Po₅)Md₂(ArBi₂)
100%
IoT botnet implant with C2 and persistence
100%
UPX packed binary
55e231d9583fbd2e372ac0f8ef6f5fa97cee1ecd30a934c8d8811328f3601585
✓
K(Mc)O₄(CErIP₄)H₆(F₈Cm₁₄Cr₃Db₂Os₄Po₈)Md(Bi₂)
99%
init/bootdos/multi-vector
100%
UPX-packed ELF with HTTP C2
13967a1f8467a05a8a162856547c123359029fccf00c8c2bb1988daa1a451d86
✓
O₃(CP₄Er)H₆(F₅Cm₇Cr₂DbOs₃Po₄)Md₂(BiHe)
100%
IoT botnet with C2 and persistence
41ceaf7915fb607afcc0d34043817aab3c81b41b81731901c43e87d93729d600
✓
K(Mc)O₄(CErIP₄)H₆(F₈Os₄Cm₁₄Cr₃Db₂Po₈)Md(Bi₂)
100%
Mirai DDoS botnet malware
fac726e1698ee567b2b25106976e103561852a56d63831cf05f66ec05a64be4e
✓
O₃(CP₄Er)H₆(F₅Cm₈Cr₂DbOs₃Po₈)Md₂(BiHe)
100%
IoT botnet with C2 and persistence
b949007bb4e1adcd2026c61f79d379dc349bfec86fdad8baddeea64356159ca5
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
Multi-stage webshell and rootkit
07a947fb7c053feb7f1acdc48f4802c5d8578434afab3251c05c9812d32beefb
✓
K(Mc)O₄(CErIP₄)H₆(F₈Cm₁₄Cr₃Db₂Os₄Po₈)Md(Bi₂)
100%
Mirai botnet DDoS malware
840d6303cf94d4dd8d2bc8d4718535efaee87be41a36b8278f4460efd0e4b912
✓
O₃(CP₄Er)H₆(F₅Cm₇CrDbOs₃Po₅)Md₂(ArBi₂)
100%
IoT botnet implant with C2 and persistence
bc6cb72c52a29f3f250446456f41d68c789a56d92bbf19e735cf1f10c33a19ca
✓
O₆(P₂As₂CErDyLa)H₅(Cm₉DbF₁₀Os₅Po₄)Md
100%
Multi-stage backdoor with C2 and persistence
100%
Malicious dropper script
2c87f833e38c2c3988aa02d7e3e442c7ec0ae6029e68e72f6948613f22b341ea
✓
O₆(P₂As₂CErDyLa)H₅(Cm₉DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, C2, persistence
3347e8464e66db963347176e516120c35388a339175a2234c6730e5576f4dd3d
✓
O₃(CP₄Er)H₆(F₅Cm₇CrDbOs₃Po₅)Md₂(ArBi₂)
99%
init/bootbotnet/iot
100%
Downloads and executes raw IP payloads
8421a7f0fe6396845762246f5cc19a7c1a7124ff80d5aaeac69cd91b0fc815cf
✓
K(Mc)O₄(CErIP₄)H₆(F₅Cm₇CrDbOs₃Po₄)Md(Bi)
100%
Mirai DDoS botnet malware
99%
upx/decompression-failedpack/detect
100%
IoT botnet with C2 and persistence
99%
upx/decompression-failedpacker/upx
6852d14ddab95ad43b8122b6752371c59b4a46c88c9a5885108acefbee23662f
✓
K₂(Mc₂Li)O₂(IAs)H₄(Cm₄F₆Os₃Po)Md₂(ArBi₂)
100%
Daredevil botnet binary
6e54d7092839436f3da754c81a2bc21e951576208ddea941cada6944f51fa679
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, C2, root persistence
9c3cda2706df64ffbc82d166c54513e1ae021dca243a49e5e505ee4c8341f90e
✓
K₂(Mc₂Li)H₄(Cm₃F₆Os₄Po₅)Md₂(BiBk)Th
100%
Daredevil botnet malware
67%
UPX packed binary
551c920f4e51f0b8f0af4212465feeecda249061ad107ccfc53ca532c09d138f
✓
O₆(P₂As₂CErDyLa)H₅(Cm₉DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, C2, persistence
100%
Malicious dropper script
64f287ae4e695ac0adfadcf516773d8ad7a60bc7174005903cb443ec86d3066a
✓
K₂(LiTe)O₈(AsEr₉ILaP₂XeDyPr)H₅(Cm₁₀F₁₄DbOs₆Po₃)Md₃(PtBk)Th
100%
Linux rootkit with C2 and persistence
13f8ed3c1d7a6c8a5f86d67c8e4da54453ec52fcf6e19bba70bcf7890fab2290
✓
K₂(Mc₂Li)O₂(IAs)H₄(Cm₄F₆Os₃Po)Md₂(ArBi₂)
100%
Daredevil botnet binary
83%
IoT bot raw socket flooding
79c8c8f24ee8ed9fcfd100149a792db90e4c6d1cbaf40dcf095a478f1f3c483c
✓
K₂(LiTe)O₈(AsEr₉ILaP₂XeDyPr)H₅(Cm₁₀F₁₅DbOs₅Po₃)Md₂(Bi)Th
100%
Linux rootkit with C2 and persistence
884d4aed509b9eba0c7b7cb4e0d98153707dcba323c95a28cbc38629e23d5de6
✓
K₂(Mc₂Li)O(As)H₄(Cm₂F₆Os₃Po)Md₃(ArBi₂Bk)Th
100%
Daredevil Mirai botnet payload
9ed802164ad6e3782665fbd4e127c056568928988d94e370c6666c052bc2ed93
✓
K(Te)O₇(Er₉As₂ILaP₂DyPr)H₅(Cm₁₅F₁₆DbOs₆Po₈)Md₄(ArBi₂He)
100%
eBPF rootkit with C2 and persistence
a8475accf7afb3b9dbed6b81fd941842f8e5c158b7db1cea9fd6875518d2ec56
✓
K₂(LiTe)O₈(CAs₂Er₉ILaP₂DyPr)H₅(Cm₈F₁₄DbOs₅Po₂)Md₃(ArBi₂)
100%
Rootkit with C2, persistence, hiding
bc804bda57f853dab5efe5dad9926b361211b32c5fb5392833bcb62fc609a722
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, C2, root persistence
d487bd1fa0855abac116c4ce865a3077e5fa2a32c33c94b3196b5a7932f71936
✓
K₂(LiTe)O₇(Er₉AsILaP₂XePr)H₅(Cm₁₁F₁₄DbOs₈Po₈)Md₃(BiBk)Th
100%
Mirai botnet with rootkit and C2
100%
Mirai botnet binary
eacdd45f881888d24e377b8de292525ca3d3fee28eec1c218a09ff95f1cdcffd
✓
K₂(LiMc)O₈(As₂EuI₃PErXeCaDy)H₇(Cm₁₃Cr₁₂F₈MgOs₇Po₇U)Md₃(Bi₃He)Th
100%
SSH backdoor with embedded XMRig miner
ee0040d0a0bfc4dcc22b58f4316a4534696d0db69cbaa02b6aabbd41b117e58d
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, C2, root persistence
eecaadd5291b82dfc41ecc4aa3a8c8664c76da196ca587a15087846a498b6498
✓
K₂(LiTe)O₈(AsEr₉ILaP₂XeDyPr)H₅(Cm₁₂F₁₅DbOs₅Po₃)Md₂(Bi)Th
100%
Linux rootkit with C2 and DDoS
f6ad4d0dfad475a63f4ea9fadcf44b97aaa38382585abd0bfb2f1ce186e9026b
✓
O₆(Er₉AsILaP₂Pr)H₅(Cm₁₅F₁₈DbOs₇Po₈)Md₄(ArBi₂Bk)Th
100%
Linux rootkit with C2 and persistence
115a0417eb49822f8fade16ff1c76bf0b913104b178f69c5102e3f20feb10140
✓
K₂(LiTe)O₆(As₂Er₉ILaP₂Pr)H₅(Cm₇F₁₄DbOs₆Po₂)Md₄(ArBi₂Bk)Th
100%
Linux rootkit with C2 and persistence
83%
IoT bot raw socket flooding
18c1502de9ebf3b8fb22c4fb532ae2887a18b3694e0107ef5a042f6055e2d0c1
✓
K(Mc₂)O(Al)H₄(Cm₁₀F₇Os₅Po₃)Md₂(ArBi₂)Th
100%
Mirai botnet malware
ec7553c8ad8bc66b568410fb9ac7ea36bd772f7f1694875f40e5a099d0c3bda3
✓
O₆(C₃P₂As₃ErDyLa)H₅(Cm₁₀Db₃F₆Os₅Po₄)MdTh
100%
Multi-stage FreePBX backdoor dropper
100%
UPX packed ARM binary
100%
UPX packed binary
0dd39fd5a0b389fc05abe442df584bf14a80bc6c52d8e27312c4237f120fd4f6
✓
K₂(McLi)O₄(IAlErP₂)H₅(Cm₆DbF₇Os₇Po)Md₃(Bi₂Bk)
100%
Mirai botnet with persistence and C2
441c962281eb649eb01f1e7a8b1af5bbd85ffa8aca325a3cc378529d9c99d4f5
✓
O₆(P₂As₂CErDyLa)H₅(Cm₉DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, C2, persistence
100%
Downloads and executes raw IP payloads
100%
Mozi botnet, Tsunami trojan
100%
Downloads and executes raw IP payloads
8c78b18ca8e2c9a62e77fc7d5927fdcb0c1bc9128b131abd3238a9cfac4834ee
✓
O₆(P₂As₂CErDyLa)H₅(Cm₉DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, C2, persistence
939a999e03e1f80f3eb8e4e04b93c42339261e463e16582c2cccda1a28b57a8a
✓
K₂(LiMc)O₆(C₃DyAsEr₃I₂P₃)H₅(Cm₁₀F₁₀DbOs₅Po₄)Md₃(Bi₂)
100%
IoT botnet with C2 and persistence
cf6b1f52c77fd661789023e16a3bac1b757818ff814b4e2db25a577b5f4e795e
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
webshell/authaccount/create
d65a280b0afe28b6e51484988c3b6dbe86372a5dd47b4fef1a5fa1836f4a300f
✓
K₂(McLi)O₆(CIAlErAsP₂)H₆(Cm₆CrDbF₇Os₈Po₂)Md₃(ArBi₃)
100%
attack/botnetbotnet/iot
e935435d050857463d493b12575e58c21313d71ca5a7d9946d944bac517f9369
✓
K₂(McLi)O₅(IAlErAsP₂)H₆(Cm₇CrDbF₆Os₇Po)Md₃(ArBi₂)
100%
Mirai botnet with DDoS and persistence
f4da5e15023114e0dd0dede7df30877784beae270bceadfb795351b39fdce367
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₁Os₅Po₄)Md
100%
Webshell, root account creation, C2
f950e77ec26b79ef19b048f680ea1f7766a556b82fbabcedc18c971c0af63338
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, root persistence, C2
100%
Downloads and executes raw IP payloads
bc852a450ebe388f8c170f37293bb6a2ec9c5b8bf0e205325db435890588967b
✓
K₂(McLi)O₆(CIAlErAsP₂)H₆(Cm₆CrDbF₇Os₈Po₂)Md₃(ArBi₂)
100%
Mirai botnet implant with C2 and persistence
7c82112529268649005f48216dc9f194ab3429329ee509d283a30e5576b9714c
✓
K₂(McLi)O₄(AlErIP₂)H₅(Cm₅DbF₆Os₆Po)Md₄(ArBiBk)Th
100%
Mirai botnet with Discord C2
fb9830c5d2eb20fba5ee606a3a6489694e38fa9a60fd0af5a39a13a70a1b7ecf
✓
O₆(C₃P₂As₃ErDyLa)H₅(Cm₁₀Db₃F₁₁Os₅Po₄)MdTh
100%
Multi-stage FreePBX webshell dropper
0a859a5a3e06a22b7f907c13e94fbc030be76d307a1178c2870426ea10dff26a
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, root persistence, C2
91586ada5fde2c340ff9790f9a3804843a2e501c252f06cf4e11156bf3095268
✓
K₂(McLi)O₃(AlErP₂)H₅(Cm₅DbF₆Os₆Po)Md(Bi)Th
100%
Mirai botnet with C2 and persistence
587b0fe097b5be07f9711b41cdd20cb7732d744abd37b86f229ed2200238272e
✓
O₆(P₂As₂CErDyLa)H₅(Cm₉DbF₁₀Os₅Po₄)Md
100%
Webshell, backdoor, C2, persistence
99%
trojan/miraiattack/botnet
99%
trojan/miraiattack/botnet
99%
attack/botnet
100%
delivery/download-execute
99%
attack/botnet
65999cd4c92e97ae82d464366918a70a4d3dcf00fd69a1c56f90fa37b9c24782
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
webshell/authaccount/create
99%
Source engine bot malware
99%
upx/decompression-failedpacker/upx
0ac4152a60a7a373d0816fda27a5a522c18e5c972f180a0bdeab4bd9449e318f
✓
O₃(CP₄Er)H₆(F₅Cm₇Cr₂DbOs₃Po₄)Md₂(BiHe)
100%
IoT botnet with C2 and persistence
20b7849f1b98ff63fc9ae31d2da8a8145e496815bcd5a228f01061063f46216c
✓
K(Mc)O₄(CErIP₄)H₆(F₈Cm₁₄Cr₃Db₂Os₄Po₈)Md(Bi₂)
99%
init/bootdos/multi-vector
32954f6ff197f408b847d358030506ea1e9b8f955fe1ac16eabd3ea7313cfcf6
✓
O₇(C₃P₂As₃ErDyLaXe)H₅(Cm₈DbF₁₀Os₅Po₄)Md
100%
webshell/authaccount/create
7c7b9c33ece837a45ece5a982740b3b2d6cd44fe93664dd7fb68e97103359c43
✓
K(Mc)O₄(CErIP₄)H₆(F₈Cm₁₄Cr₃Db₂Os₄Po₈)Md(Bi₂)
99%
init/bootbotnet/iot
100%
delivery/download-execute
b94c5392ef73b9b3a8a930005f2d48d273e3179553131bc294562ac64c7effa1
✓
O₃(CP₄Er)H₆(F₅Cm₇CrDbOs₃Po₅)Md₂(ArBi₂)
99%
init/bootbotnet/iot
99%
upx/decompression-failedpacker/upx
99%
upx/decompression-failedpacker/upx
f878e25084eb4aa2e9f90addbc26bf26a1a64d3f004ce89fbe81476b6e0492a3
✓
O₃(CP₄Er)H₆(F₅Cm₇CrDbOs₃Po₅)Md₂(ArBi₂)
99%
init/bootbotnet/iot
99%
upx/decompression-failedpacker/upx
100%
IoT botnet with C2 and persistence
99%
upx/decompression-failedpacker/upx
99%
upx/decompression-failedpacker/upx
0d13d3665a7b952d21184d806ad8e0f8b173dd4d5102a1dff1a62f24f7bf5c05
✓
O₆(C₃P₂As₃ErDyLa)H₅(Cm₁₀Db₃F₁₁Os₅Po₄)MdTh
100%
account/createwebshell/stager
99%
upx/decompression-failedpacker/upx