hxxp://54.177.246[.]246/t[.]msi
Lots of stuff bundled here..
hxxp://185.254.198[.]187/ransomware[.]exe
hxxp://185.254.198[.]187/stealer[.]exe
UwU What could they be?
hxxp://1.15.143[.]227:8080/BlackMoon[.]dll
Some of the samples I'm uploading now may not be there any more but if they are I would extreme caution as always. This one is ransomware for sure.
hxxp://177.142.134[.]10:8000
* [a.bat](a.bat)
* [caddy.bat](caddy.bat)
* [caddy.exe](caddy.exe)
* [Caddyfile](Caddyfile)
* [gdfgd](gdfgd)
* [gfs.txt](gfs.txt)
* [hidden.vbs](hidden.vbs)
hxxp://59.110.219.204:8081/Cobalt_Strike_4.7[.]zip
http://59.110.219.204:8081/K8_CS_4.4[.]zip
hxxp://59.110.219.204:8081/TeamServer[.]zip
Not sure what you'll find in the last one but worth a look.
Remember to do all work in a VM!