HKTL_CobaltStrike_Beacon_Indicators_Aug20_2

Rule Info

Tags
['T1075', 'EXE', 'S0154', 'FILE', 'HKTL']
Name
HKTL_CobaltStrike_Beacon_Indicators_Aug20_2
Minimum Yara
1.7
Rule Hash
6936dc6adad1bf8ef4b4f61d75f660be
Av Ratio
17.14
Score
75
Author
Florian Roth
Date
2020-08-03
Description
Detects CobaltStrike beacons
Required Modules
[]
Reference
Internal Research

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
15
Suspicious (< 10 engines)
26
Clean (0 engines)
3

Rule Matches

Hash
Timestamp
Total
Positives
VT
851f1fab02aa1bc4f64d5f766a925bba6736769fd498fc789c56b4e52ce1f1d0
2021-06-09 17:44:26
69
44
49f74fc353874133f5df9d0a3e31a369cabb626206a4b9c9a9d55916c2383405
2021-06-08 09:05:53
70
31
f9a3cbb553d6ddd056fb03e0e7e8580f9eaec56e859c9de359d41b2655afaae6
2021-06-03 21:22:33
66
1
250afc7dad9f6a07b912321f07f5c436e816f81136eb9e5aba26565b95a53d6a
2021-05-05 20:24:44
69
11
651a79f224c2fda1225291cc2ae6c7238c263934083fc111b5f7245c27d321bf
2021-04-28 04:17:36
70
35
a50dfe96d241dfb9d7868f738744e9581e162024e6ca4741be7c30cf5fd688b4
2021-04-22 14:18:12
66
2
fd036731506022319502d6e0cd0ba8821e4210eb912bc40aef1fddf37130adce
2021-04-22 10:39:43
69
15
9abfe7f118b2bfc9d940050bb5e10a5cb46abf81b92f4bf6aeeedec291015e86
2021-04-21 16:17:29
62
23
c2c2d8aab3b2c72e34767d16ee029a09035851b9aa6773ca5d83804aa2cfe911
2021-04-15 08:49:06
69
16
618d5e2ecb1cc0e94a8d27bcd340ff56947e9b7a11782e41ca3bc9305f478479
2021-04-10 14:40:42
69
6
885328bd3167f5ceb358551c10d481633e8c0cac599ae9eecde6ec878d2c492f
2021-04-05 06:19:15
70
45
07e287766b32359141406351ab9a8f6a85fddeed2fffae3265d5b0d90ba614ab
2021-03-17 07:01:01
68
45
5cfac855315ac87efc08d9d66ecd26e125058e3fbb5f1d72d245880b4048316c
2021-01-27 16:43:24
69
1
c0ab85c3f2a6def245802c9764cd695b847c37afb1d125f02158069981562f1d
2021-01-27 16:42:37
70
0
37cbfca8617c4d8a2b2f1858032733a62dc0ac7e661dd3236f75ec7cfc71acfd
2021-01-27 16:42:15
69
0
f72f1142ff5892922cae0370e0adc636eb5235cb5eeb24743432fd15b1446967
2021-01-12 06:14:34
71
5
a81c2abdbd99edcb4042f54fb8c7475ef337c2e1697e98817d05c87f2b527204
2020-11-18 15:35:35
72
34
8d632a85aeb1d80411254547f6a4df4c5e55e601a9cf913aca2f780bfe5ce3e5
2020-11-16 19:55:24
72
3
1a87a3841e36e04e9fb90b80e24bab103fe3c618b9a2720ac2a8578b6ac06b68
2020-11-16 19:54:07
72
2
7cf6003f769910e42c4b5d846f212cf944ae997fc5ddfcf73daafafe67b4b403
2020-11-16 19:52:45
71
2
1f2e03299bf618d5f6eafe9eb2ccb9396d8e258a328f383f92fd54212c349c83
2020-11-16 19:51:05
72
3
af15dc7209cde8e372ccead2386fb99cc8ee85e4faa9445a05e93d1d6bc03adc
2020-11-16 19:49:15
63
1
697b5b65334ccee4fefef90cdc83904c8c2d6e1572d70205623d509f7f56ba0e
2020-11-16 19:48:14
70
3
fec8bb590646dd2e58860660ae4777181a77e12e034828688c4a4cfb1e8455cb
2020-11-16 19:47:03
72
3
3b6b90adc1f8cb9c2bd638be804dfa466175cc9e02a2040345737a3a2819c724
2020-11-16 19:46:36
72
1
6edf11bd0c604e6fc83886b51a7abf8cdb3d132b05c7800ec521ccf12cd5ae5a
2020-11-16 19:46:07
72
3
c9cdae92e58be4e8a69a5a93ec7851976e98338a2595816689c841b86f8fc083
2020-11-16 19:41:06
72
3
95659b6793d3fa65bb4f5253c7bd39b475ecafb1b17968bb00e7d2bce42a6a21
2020-11-16 19:40:27
72
3
dda09d608abbfbe19e2b15a9a098de246755df2ef3f6a3bbfd29b76ee225137c
2020-11-16 19:39:32
72
3
c0440acd58dcbae66cf11ec5d84162d8a417287c392796bab92e984786173d83
2020-11-16 19:37:10
72
3
69e0e67fa06ad4202ddc88f2224a4315931712b09ea7acff54e92cd5c093e8cd
2020-11-16 19:34:41
71
3
3508d03474cae3f70e336ebf65d3cbda63d8feaf28ec64ab5f7046babf05a1d3
2020-11-16 19:33:58
71
4
cd0e9110d5a21eaa3d2d10bf60de002fa735b546d54b8263732fe8cc11048111
2020-11-16 19:33:15
72
4
1c2c120df5c584a536f806d8c19998b04358a6f25f75161c05a36e6524ab4d05
2020-11-16 19:31:18
72
3
fa098e3898def05d75e275e2e9cb36c397bfd303a4826f6b8f49ccaef7f1f27e
2020-11-16 19:29:34
70
2
0936e882b703da4c94d5e5b893de9546bd93941664a8db48aa73bd5573c5395b
2020-11-16 19:28:13
71
6
8fee6579a61c5d937c37f2cd2f2e1ebe4316e6a0fd95289344a31140d142189b
2020-11-16 19:28:08
71
3
3bfd25e9eed08c170235c8f5882477497aead81b1fea1b924b298df83aa5bf18
2020-11-10 05:35:20
72
3
82d1ff7c99f597d6ad5361ab7abcc2d319fc474d821c4fe85a6f9405c5a8c325
2020-10-10 08:49:24
68
41
e721144830b9411770ca63aa18daa437f93e9ea2f0ddc15c4e753312c70e6a42
2020-09-01 11:53:46
68
0
dac4c2e5318bf0feca535b2116bd48e72d8f36ff7ec8f3bd176fd7e57bd37fc1
2020-08-18 11:41:33
69
37
290ea0fec256757347cae0efbf8504ded52284c724196c89da8c4534ffae8544
2020-08-12 00:47:25
68
16
0cd4555605fdc5ad3dc2f61f5a431f48ebb2b2eb1b5c0935828e0eb0f2171ca7
2020-08-12 00:32:37
68
18
b532927292b61950d37238ff444469505018ea1d0e552d63c767139ce0e3f939
2020-08-11 01:19:50
71
35

Rule Matches per Month (last 24 months)