diff --git a/conf/db.ver b/conf/db.ver index ba81ffb..55dd1c0 100644 --- a/conf/db.ver +++ b/conf/db.ver @@ -1 +1 @@ -110810112018 +175614042019 diff --git a/conf/maldb.db b/conf/maldb.db index 6b391fa..d511602 100644 Binary files a/conf/maldb.db and b/conf/maldb.db differ diff --git a/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.md5 b/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.md5 new file mode 100644 index 0000000..9ad0f02 --- /dev/null +++ b/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.md5 @@ -0,0 +1 @@ +MD5 (Sample_5b7da8bfa0342e5a6cf5bacc.exe) = 9fbdc5eca123e81571e8966b9b4e4a1e diff --git a/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.pass b/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.sha b/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.sha new file mode 100644 index 0000000..7940322 --- /dev/null +++ b/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.sha @@ -0,0 +1 @@ +7a5b7c5378e0afcc77098a87358e4f6a032d3b00 Sample_5b7da8bfa0342e5a6cf5bacc.exe diff --git a/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.zip b/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.zip new file mode 100644 index 0000000..134181e Binary files /dev/null and b/malwares/Binaries/Win32.DarkTequila/Win32.DarkTequila.zip differ diff --git a/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.md5 b/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.md5 new file mode 100644 index 0000000..4ef1149 --- /dev/null +++ b/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.md5 @@ -0,0 +1 @@ +MD5 (Win32.KeyPass.bin) = 6999c944d1c98b2739d015448c99a291 diff --git a/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.pass b/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.sha b/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.sha new file mode 100644 index 0000000..200fea0 --- /dev/null +++ b/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.sha @@ -0,0 +1 @@ +d9beb50b51c30c02326ea761b5f1ab158c73b12c Win32.KeyPass.bin diff --git a/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.zip b/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.zip new file mode 100644 index 0000000..e6d98ff Binary files /dev/null and b/malwares/Binaries/Win32.KeyPass/Win32.KeyPass.zip differ diff --git a/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.md5 b/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.md5 new file mode 100644 index 0000000..905f6e0 --- /dev/null +++ b/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.md5 @@ -0,0 +1 @@ +MD5 (Win32.MyLobot.bin) = c5307c17eeda787432f82f1d648a368c diff --git a/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.pass b/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.sha b/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.sha new file mode 100644 index 0000000..1e79cd3 --- /dev/null +++ b/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.sha @@ -0,0 +1 @@ +2a6b0f3a422a49e450cc39354fd687084c8a209e Win32.MyLobot.bin diff --git a/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.zip b/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.zip new file mode 100644 index 0000000..b94e6a8 Binary files /dev/null and b/malwares/Binaries/Win32.MyLobot/Win32.MyLobot.zip differ diff --git a/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.md5 b/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.md5 new file mode 100644 index 0000000..ba9d0ca --- /dev/null +++ b/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.md5 @@ -0,0 +1 @@ +MD5 (Sample_5c9918c51df8a33279a11b41.bin) = 38b1eef05500d1575a36a4f9a526dcbe diff --git a/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.pass b/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.sha b/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.sha new file mode 100644 index 0000000..3979bf5 --- /dev/null +++ b/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.sha @@ -0,0 +1 @@ +c61602d94d2b87542789cdc5abf85dd97920f0af Sample_5c9918c51df8a33279a11b41.bin diff --git a/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.zip b/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.zip new file mode 100644 index 0000000..4a568df Binary files /dev/null and b/malwares/Binaries/Win32.ShadowHammer/Win32.ShadowHammer.zip differ diff --git a/malwares/Binaries/Win32.Triton/Win32.Triton.md5 b/malwares/Binaries/Win32.Triton/Win32.Triton.md5 new file mode 100644 index 0000000..ffa3aa9 --- /dev/null +++ b/malwares/Binaries/Win32.Triton/Win32.Triton.md5 @@ -0,0 +1 @@ +MD5 (Sample_5c1bf66ee2758b166fc5a601.bin) = 1904cad4927541e47d453becbd934bf0 diff --git a/malwares/Binaries/Win32.Triton/Win32.Triton.pass b/malwares/Binaries/Win32.Triton/Win32.Triton.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.Triton/Win32.Triton.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.Triton/Win32.Triton.sha b/malwares/Binaries/Win32.Triton/Win32.Triton.sha new file mode 100644 index 0000000..ba99f66 --- /dev/null +++ b/malwares/Binaries/Win32.Triton/Win32.Triton.sha @@ -0,0 +1 @@ +aafa932eda97859e2b72772a3a8581760e860a46 Sample_5c1bf66ee2758b166fc5a601.bin diff --git a/malwares/Binaries/Win32.Triton/Win32.Triton.zip b/malwares/Binaries/Win32.Triton/Win32.Triton.zip new file mode 100644 index 0000000..cf685ae Binary files /dev/null and b/malwares/Binaries/Win32.Triton/Win32.Triton.zip differ diff --git a/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.md5 b/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.md5 new file mode 100644 index 0000000..21a18b0 --- /dev/null +++ b/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.md5 @@ -0,0 +1 @@ +MD5 (Win32.Turla.v1.zip) = 3c2dfe47b8f5f80055a382309f3622d0 diff --git a/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.pass b/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.shasum b/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.shasum new file mode 100644 index 0000000..63cd98c --- /dev/null +++ b/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.shasum @@ -0,0 +1 @@ +24fe1313ca81d11242464c528afa992c84eb8e33 Win32.Turla.v1.zip diff --git a/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.zip b/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.zip new file mode 100644 index 0000000..d28d64e Binary files /dev/null and b/malwares/Binaries/Win32.Turla.V1/Win32.Turla.v1.zip differ diff --git a/malwares/Binaries/Win32.XAgent/Win32.XAgent.bin.zip b/malwares/Binaries/Win32.XAgent/Win32.XAgent.bin.zip new file mode 100644 index 0000000..7081181 Binary files /dev/null and b/malwares/Binaries/Win32.XAgent/Win32.XAgent.bin.zip differ diff --git a/malwares/Binaries/Win32.XAgent/Win32.XAgent.md5 b/malwares/Binaries/Win32.XAgent/Win32.XAgent.md5 new file mode 100644 index 0000000..f61c989 --- /dev/null +++ b/malwares/Binaries/Win32.XAgent/Win32.XAgent.md5 @@ -0,0 +1 @@ +MD5 (Win32.XAgent.bin) = 2f6d1bed602a3ad749301e7aa3800139 diff --git a/malwares/Binaries/Win32.XAgent/Win32.XAgent.pass b/malwares/Binaries/Win32.XAgent/Win32.XAgent.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.XAgent/Win32.XAgent.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.XAgent/Win32.XAgent.sha b/malwares/Binaries/Win32.XAgent/Win32.XAgent.sha new file mode 100644 index 0000000..3a76164 --- /dev/null +++ b/malwares/Binaries/Win32.XAgent/Win32.XAgent.sha @@ -0,0 +1 @@ +63fc853d44808a4a00892239e3bc6da4e9552570 Win32.XAgent.bin