HKTL_CobaltStrike_Beacon_Indicators_Aug20_2

Rule Info

Rule Hash
6936dc6adad1bf8ef4b4f61d75f660be
Required Modules
[]
Av Ratio
12.35
Reference
Internal Research
Author
Florian Roth
Score
75
Name
HKTL_CobaltStrike_Beacon_Indicators_Aug20_2
Minimum Yara
1.7
Description
Detects CobaltStrike beacons
Date
2020-08-03
Tags
['HKTL', 'T1136', 'EXE', 'T1075', 'S0154', 'FILE']

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
6
Suspicious (< 10 engines)
21
Clean (0 engines)
1

Rule Matches

Positives
Total
Hash
Timestamp
VT
34
72
a81c2abdbd99edcb4042f54fb8c7475ef337c2e1697e98817d05c87f2b527204
2020-11-18 15:35:35
3
72
8d632a85aeb1d80411254547f6a4df4c5e55e601a9cf913aca2f780bfe5ce3e5
2020-11-16 19:55:24
2
72
1a87a3841e36e04e9fb90b80e24bab103fe3c618b9a2720ac2a8578b6ac06b68
2020-11-16 19:54:07
2
71
7cf6003f769910e42c4b5d846f212cf944ae997fc5ddfcf73daafafe67b4b403
2020-11-16 19:52:45
3
72
1f2e03299bf618d5f6eafe9eb2ccb9396d8e258a328f383f92fd54212c349c83
2020-11-16 19:51:05
1
63
af15dc7209cde8e372ccead2386fb99cc8ee85e4faa9445a05e93d1d6bc03adc
2020-11-16 19:49:15
3
70
697b5b65334ccee4fefef90cdc83904c8c2d6e1572d70205623d509f7f56ba0e
2020-11-16 19:48:14
3
72
fec8bb590646dd2e58860660ae4777181a77e12e034828688c4a4cfb1e8455cb
2020-11-16 19:47:03
1
72
3b6b90adc1f8cb9c2bd638be804dfa466175cc9e02a2040345737a3a2819c724
2020-11-16 19:46:36
3
72
6edf11bd0c604e6fc83886b51a7abf8cdb3d132b05c7800ec521ccf12cd5ae5a
2020-11-16 19:46:07
3
72
c9cdae92e58be4e8a69a5a93ec7851976e98338a2595816689c841b86f8fc083
2020-11-16 19:41:06
3
72
95659b6793d3fa65bb4f5253c7bd39b475ecafb1b17968bb00e7d2bce42a6a21
2020-11-16 19:40:27
3
72
dda09d608abbfbe19e2b15a9a098de246755df2ef3f6a3bbfd29b76ee225137c
2020-11-16 19:39:32
3
72
c0440acd58dcbae66cf11ec5d84162d8a417287c392796bab92e984786173d83
2020-11-16 19:37:10
3
71
69e0e67fa06ad4202ddc88f2224a4315931712b09ea7acff54e92cd5c093e8cd
2020-11-16 19:34:41
4
71
3508d03474cae3f70e336ebf65d3cbda63d8feaf28ec64ab5f7046babf05a1d3
2020-11-16 19:33:58
4
72
cd0e9110d5a21eaa3d2d10bf60de002fa735b546d54b8263732fe8cc11048111
2020-11-16 19:33:15
3
72
1c2c120df5c584a536f806d8c19998b04358a6f25f75161c05a36e6524ab4d05
2020-11-16 19:31:18
2
70
fa098e3898def05d75e275e2e9cb36c397bfd303a4826f6b8f49ccaef7f1f27e
2020-11-16 19:29:34
6
71
0936e882b703da4c94d5e5b893de9546bd93941664a8db48aa73bd5573c5395b
2020-11-16 19:28:13
3
71
8fee6579a61c5d937c37f2cd2f2e1ebe4316e6a0fd95289344a31140d142189b
2020-11-16 19:28:08
3
72
3bfd25e9eed08c170235c8f5882477497aead81b1fea1b924b298df83aa5bf18
2020-11-10 05:35:20
41
68
82d1ff7c99f597d6ad5361ab7abcc2d319fc474d821c4fe85a6f9405c5a8c325
2020-10-10 08:49:24
0
68
e721144830b9411770ca63aa18daa437f93e9ea2f0ddc15c4e753312c70e6a42
2020-09-01 11:53:46
37
69
dac4c2e5318bf0feca535b2116bd48e72d8f36ff7ec8f3bd176fd7e57bd37fc1
2020-08-18 11:41:33
16
68
290ea0fec256757347cae0efbf8504ded52284c724196c89da8c4534ffae8544
2020-08-12 00:47:25
18
68
0cd4555605fdc5ad3dc2f61f5a431f48ebb2b2eb1b5c0935828e0eb0f2171ca7
2020-08-12 00:32:37
35
71
b532927292b61950d37238ff444469505018ea1d0e552d63c767139ce0e3f939
2020-08-11 01:19:50

Rule Matches per Month (last 24 months)