diff --git a/conf/maldb.db b/conf/maldb.db index 7b2fbf0..163e499 100644 Binary files a/conf/maldb.db and b/conf/maldb.db differ diff --git a/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.md5 b/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.md5 new file mode 100644 index 0000000..feff321 --- /dev/null +++ b/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.md5 @@ -0,0 +1 @@ +MD5 (FancyBear.GermanParliament) = 77e7fb6b56c3ece4ef4e93b6dc608be0 diff --git a/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.pass b/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.sha256 b/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.sha256 new file mode 100644 index 0000000..a638e14 --- /dev/null +++ b/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.sha256 @@ -0,0 +1 @@ +f46f84e53263a33e266aae520cb2c1bd0a73354e FancyBear.GermanParliament diff --git a/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.zip b/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.zip new file mode 100644 index 0000000..43c89aa Binary files /dev/null and b/malwares/Binaries/FancyBear.GermanParliament/FancyBear.GermanParliament.zip differ diff --git a/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.md5 b/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.md5 new file mode 100644 index 0000000..640dc94 --- /dev/null +++ b/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.md5 @@ -0,0 +1 @@ +MD5 (m) = f8c8f6456c5a52ef24aa426e6b121685 diff --git a/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.pass b/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.sha256 b/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.sha256 new file mode 100644 index 0000000..aa5ec75 --- /dev/null +++ b/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.sha256 @@ -0,0 +1 @@ +83e54cb97644de7084126e702937f8c3a2486a2f m diff --git a/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.zip b/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.zip new file mode 100644 index 0000000..4191afc Binary files /dev/null and b/malwares/Binaries/Win32.APT28.SekoiaRootkit/Win32.APT28.SekoiaRootkit.zip differ diff --git a/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.md5 b/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.md5 new file mode 100644 index 0000000..3561ae3 --- /dev/null +++ b/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.md5 @@ -0,0 +1 @@ +MD5 (b81b10bdf4f29347979ea8a1715cbfc560e3452ba9fffcc33cd19a3dc47083a4) = ad44a7c5e18e9958dda66ccfc406cd44 diff --git a/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.pass b/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.sha256 b/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.sha256 new file mode 100644 index 0000000..e622694 --- /dev/null +++ b/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.sha256 @@ -0,0 +1 @@ +e2101519714f8a4056a9de18443bc6e8a1f1b977 b81b10bdf4f29347979ea8a1715cbfc560e3452ba9fffcc33cd19a3dc47083a4 diff --git a/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.zip b/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.zip new file mode 100644 index 0000000..dd8f6bd Binary files /dev/null and b/malwares/Binaries/Win32.Invincea_Tunnel /Win32.Invicea_Tunnel.zip differ diff --git a/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.md5 b/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.md5 new file mode 100644 index 0000000..6d3e83e --- /dev/null +++ b/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.md5 @@ -0,0 +1 @@ +MD5 (Win32.Sofacy.A) = ed7f6260dec470e81dafb0e63bafb5ae diff --git a/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.pass b/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.pass new file mode 100644 index 0000000..ba701bf --- /dev/null +++ b/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.pass @@ -0,0 +1 @@ +infected diff --git a/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.sha256 b/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.sha256 new file mode 100644 index 0000000..83ff0d9 --- /dev/null +++ b/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.sha256 @@ -0,0 +1 @@ +72cfd996957bde06a02b0adb2d66d8aa9c25bf37 Win32.Sofacy.A diff --git a/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.zip b/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.zip new file mode 100644 index 0000000..0016974 Binary files /dev/null and b/malwares/Binaries/Win32.Sofacy.A/Win32.Sofacy.A.zip differ