HKTL_Clash_Tunneling_Tool_Aug22_2

Rule Info

Minimum Yara
1.7
Tags
['HKTL', 'EXE', 'T1071']
Name
HKTL_Clash_Tunneling_Tool_Aug22_2
Description
Detects Clash Go-based multi-platform tunneling tool
Rule Hash
7feef48a33ffb6612633ec618926c531
Score
85
Required Modules
[]
Author
Florian Roth
Date
2022-08-27
Av Ratio
3.97

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
24
Clean (0 engines)
13

Rule Matches

Timestamp
Positives
Total
Hash
VT
2022-09-30 07:29:30
1
71
ab5b3e6ec921ea8d369b6f6fa70968993760cef1df3a621178f84778c998350d
2022-09-29 12:44:51
0
67
6fd4acb7b899b16bd2dbf867375ecb611826fe98e7ccb2c2117f511fb513a375
2022-09-29 02:44:47
3
71
adba1905f0a50fd59a0b794da9409845587f0b33fbdb457bb4eb46f8338962a2
2022-09-26 23:55:44
0
60
479d6cbfc8af40cf5d3e70fcfb1d7cb0c72184163b598e8d1031aac57e55dd03
2022-09-24 10:21:05
0
62
037027346bbecc9c1c1f107a7423b76d236db06b595aa1b9853db99c1d9cc5de
2022-09-23 12:35:09
4
71
8357068a82aeb46d6628f811296e8d7b83f81368fcc250ea70af363510eac328
2022-09-23 08:20:34
2
71
c4c87c7894f49d8b5a6f1222eddfcf1fdd9613877270f3cfbbe59aacf26655c6
2022-09-23 08:17:10
44
62
989efe2f1cd54522edcdffa60120ce04df8b6c018c4c2ca65c40353ecf4af93a
2022-09-21 06:25:09
3
70
3dafd51eb653b977687543fd4d85b8a7db85bf79b8718f51ca9aa975c7683e44
2022-09-20 00:07:09
0
60
671d9ec14a01b73acc227ada7fd7aa78ff598f68763f035cd0086721ccf2a010
2022-09-19 12:09:43
0
61
ff74aa7892c7fa641a32287e31d0ebc3bc518a000878067f3ebaea56494f8e0f
2022-09-18 16:23:07
2
70
3b9c3bfa32c31433d99950a03e4ab892a54de8eddfd102fae2124b8042eb686d
2022-09-18 07:12:58
3
70
0d7cc2f935314b77cb35cce1482428ddab72334c0cec818e273deb9ef217dcb7
2022-09-15 08:10:43
2
69
0cc67d324bc72a8c058c3b97615de5baff3a7d8cafbe322fdf2cb2fcc1d81848
2022-09-12 15:41:36
3
69
09a255b27bc7e7e85c4b370741ac862f2d1bcdb414be9d3316d214786eb17642
2022-09-12 15:40:15
0
60
e0b99f540a75cf7b9c103c2abec5ef9fca7fb9cabc089b008762d265d8e71fb1
2022-09-12 14:32:22
3
70
321c2be2be3245f1b6a889069d6034d2c01e3bac070e22d587fa41276e8221ae
2022-09-12 05:38:39
1
70
2d7f9ead0753febb65b8c24c5a3cb2dea951164e0dfe711665c77ddac2de3f8f
2022-09-12 04:50:39
0
55
33feea70272fa050a51354331e138a2e08492a32813c5275d58d39c8a98b8389
2022-09-11 22:16:46
2
70
45e5300f9cc9e5049979edaaae4439b5dbc76e876e8b844bbc48f9104eedfe28
2022-09-11 18:56:28
2
70
92e7675a429e1e0e522adb989cb115f30c7f081b98c08f62cd76b1fc261e086e
2022-09-11 07:26:07
0
59
8c02ba0196805807d8a26ef59891a263ff418d261cff8bf8710277373e8e4cef
2022-09-10 20:09:27
2
70
9fb4a07f6207f3ee7bee80105a4d66d1ef3eca664693319d0e2f944a599cad97
2022-09-10 09:52:11
0
60
d8af83a9139b92dd09ea5064c193bcf7fa0504f4005f4fe8f0a895addc47f315
2022-09-08 00:22:45
1
70
139be598b068bf16d216975f06821d1aebdf3f0bbfc18520971c465d7dec9eab
2022-09-07 13:15:35
2
70
333b3c83a8b9ea1f5a6094f667bd3ae36e3b08f4d0d851edd99ceec957e628e0
2022-09-07 10:12:59
0
60
34680364367ddfe4f87a72025caed2c288e2561671bc6c07e39f461b3dd37039
2022-09-07 06:07:52
0
60
f4d37980350879a2dcd93ec1452b3fe99eead883c4c60260540e625f6fc23e19
2022-09-07 03:08:01
0
68
c1788bab340ee60af759a56998bf435dd6601a53578db42bf3d73a3787ab679e
2022-09-03 12:54:18
4
60
e66e86e31e4bfd1a422b4b4e3fc01e6d9c9f30c750b9a635f71a0e3e62604245
2022-09-01 16:07:56
1
69
a014665a6f118228b08656151f5e26a3ef6deeea26034f95a11e9d53be4f4ce9
2022-08-30 18:30:35
5
69
7e9dfbc8089a6c17ff4f82aae9ef015d040c1708226c6b31dc46fcf81d99aff6
2022-08-30 12:12:04
2
67
90464d555e13645782ea80107a3e074a090b4015cb855c011d45a38980d7ce5a
2022-08-30 12:10:52
2
69
1cef2a7e7fe2a60e7f1d603162e60969469488cae99d04d13c4450cb90934b0f
2022-08-29 13:25:06
0
61
e72038595ff96f2593abbe4889b3bdcc61a74e2b47ebd6bf88b8ad6e51ce83a5
2022-08-29 13:17:13
2
66
5e0aefb2c670e8a7b9daa9578f9a8f43aa8987ccc16aba98cdcbc37c1102b02c
2022-08-29 13:15:51
2
67
a079a3d5201c5ea76d5dafb38c4a4aafab666590a85ac5603b6eab78a775bfcf
2022-08-29 11:08:20
1
69
0527f729a77b27513237e109c3337bfd1ab87a88fa2483198579077f9e96b13a

Rule Matches per Month (last 24 months)