HKTL_Empire_Win_CSharp_Dec19_1

Rule Info

Rule Hash
53731f0852d8dc3d317aab540855a764
Score
60
Tags
['HKTL', 'T1136']
Name
HKTL_Empire_Win_CSharp_Dec19_1
Date
2019-12-09
Required Modules
[]
Author
Florian Roth
Description
Detects Empire CSharp launcher
Minimum Yara
1.7
Av Ratio
0.21

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
0
Suspicious (< 10 engines)
4
Clean (0 engines)
45

Rule Matches

Hash
Total
Timestamp
Positives
VT
2766a04b04ba34b24ac7c5afb0fa5d5bee241cef782f03dd1a04f99694da98bd
58
2020-08-03 18:19:07
0
860469bb84182fe7744f1d0eab9f778020c5c3251306ac749996981f0f2710d0
59
2020-08-03 17:41:17
0
9cb72ac24f2d4eb0c90e38b3fe61c03dfa5b571693e4574b6f9bf964328e9f3b
58
2020-08-03 17:31:01
0
9aa34a6a6f07fffb484c8f301e8527a9ba4645e7417db430610901c65a2c3cee
59
2020-08-03 17:22:43
0
d0dcfb16f65f1ece1671f192a79ca9c08a4bf082ba7fc3decf79b85d30e1168d
59
2020-08-03 17:19:48
0
9f4e6b29ffff2937b86b18e66327adb92b7124a9b54ad46fce979d37dd6027c2
59
2020-08-03 17:17:53
0
7e3e055a39c28f43e2a4d9d3abe66dbb9e7682973a3b5d73df528268a7e01ad3
59
2020-08-03 17:08:13
0
6b782fec241a3192991a7848493ec4540036dd516e3db68ae9294437d2dcf8e0
59
2020-07-23 08:08:41
0
094648808f08f410bf0eb17a59dc27be79ada0ab45e0762ee999722eba9c9e19
58
2020-07-23 08:02:35
0
bca91880e9dd6477723b51c0c68c41845484ef136b9bd35fb60aee236ce6fdba
59
2020-07-23 07:58:41
0
75b50676dac83f8464a4f58e79239e11beca3dc45af6bc60ff24138156a1912b
57
2020-07-23 07:49:14
1
7a9211e8cbb04b9ebbbc12030bd11df8b96b789114dec7bd759d22fd87a01ac4
59
2020-07-20 14:24:57
0
52ea15f096b6953e184a63535fafaeb8d5829cd35e75b58a650c691a8e48906f
57
2020-07-20 14:14:00
0
8dec3fc65df0da17e17422325993e1abada72375adddac03555d4eff1a3fb689
58
2020-07-20 14:12:49
0
657ecf32aa6d6c48381f4f88cf0bba4112829447af67925489269ceb2661fe50
59
2020-07-20 14:05:30
0
b2bfbdea785f5654055c1d141fd7c1384d68e284a5ec42c552b3afe982baa868
59
2020-07-20 14:04:44
0
b3482881cfb94d4cd13fedf4aa7a33af3104628eaeabb2fa6b96ca538c5c2244
59
2020-07-20 14:04:43
0
9cf86e5a0d64e9f2049f702840d884561e5583b7663ebb18b3fadbc801bec31c
60
2020-07-20 13:39:41
0
f16349e22c3d2b7d080b668e45c565001a8b9a5d9c2a03f37e05d09e32c2e518
58
2020-07-20 13:38:21
0
79904fcae675e6ca8fa621f72f6900b0521da085a7bfeec0633b6647f3e0e56a
57
2020-07-20 13:04:11
0
caaa030f9bef29d09825b739c529c0a152be70607ab22f1d0e7e6458a9f15551
60
2020-07-20 13:03:39
0
4971c670bc0a4dc7d859a505e15c2484200db1e0a7cbeef2b616e2f1f57ebbd8
59
2020-07-20 13:02:52
0
3524ed6b8587f1ca890414d07c4b9fa91903fca39d465961d11d4000dc095d00
59
2020-07-20 13:02:18
0
b0e9b33787688cb3008010574d1ac80bdd256b315f578dae2b870ba1eaab7b69
59
2020-07-20 13:01:56
0
5f25aa0837344b20a487a75d5618a4e2e706e161d3fee25e567f7b627f7117b7
57
2020-07-20 13:00:28
0
c33313e2c5181e0c82aa0763c7ad58841d1f2bca67d8a38c5f5da202aaf7ce53
58
2020-07-20 13:00:28
0
46be6e44b631dc90e65e35f64e6300df510ba9d6722215d79d184cfb61a27b22
59
2020-07-20 13:00:07
0
194f402d7af667151347647ba40bbf68a7122b94a49e61b415ff32b2060ec1ea
59
2020-07-20 12:42:47
0
f4480fd6304c4475c74e6fb2757748c13503b739be79bd52fe9ffe4f50f4cae6
52
2020-01-13 19:36:09
0
25246dc0a7914b5f7c677c1da65749fb3d222a697a5da1bee4c2273ea97c797d
60
2020-01-13 18:52:07
0
1de9243bd07d7b298361e4af3f8690d3bb6c0d3e3b04ac4455ee8f552e2c349e
57
2020-01-13 18:06:36
3
2e73418a3a77633b70e111991e0f7540d385017f9b4870c2d4b57b85b01923e4
59
2020-01-13 17:30:07
0
7db0621d30ecf7f1687fb80ad0161d1293531a5c1c158959b6388e8ae380aa23
59
2020-01-13 17:01:07
0
62ea8580687e6c9602c233b356931d9ae9194af893ea186fa43347050d4028e5
59
2020-01-13 16:59:14
1
c5bd57155879a75180a85639942e6b2656dffce1178ea8b71d60b70d75e9e938
58
2020-01-13 16:12:15
0
01a753e6ea0c754011acd673ce0b19dc537729b778273a049fe15de409d4f85d
60
2020-01-13 15:52:44
1
cdf04dbb24fc25d10940741861336a7329b16198be8deaa6b3e0eaa0b1840195
60
2020-01-13 15:33:57
0
73a5129774eb5f9d7e591957f056c2bf4454e85d3bf6d8d6a913ad164c322cc1
58
2020-01-13 15:33:51
0
2bcb7bdcc5c6511b832d6aea3b2757bffebe8171ddf064887ce96fa9b114fc59
59
2020-01-13 15:18:37
0
2128cb5ed71b9e1d6c39f733e253ffc5cc3cd960c08c9e882f54b8f5c43fdd1e
58
2020-01-13 14:49:09
0
bfb28e19edbe47aafd46f4572f54e0d0a5690efa98124a238741e82f0a2f2bb6
57
2019-12-11 12:53:38
0
67ef1a2a7d1a615537e569bf0dc72041660da64640886e4fad94d62aeae7da96
57
2019-12-11 12:34:35
0
cf2257e74fff0f101352e67f4052f860add2799c0a62852684d35adda4f0e29d
57
2019-12-11 12:29:36
0
86eb06f5cf68875c57d8b4baed559577821f7f87fe3a102fa48b7bf854d8a61b
57
2019-12-11 12:19:09
0
79a73c9f23ad34498254ad03643fecba3c1575f08dccb3b7515fca2b73e23253
58
2019-12-11 12:14:15
0
0b242f812c1d94ea7d908d468b50361dc43e6bce08f890fc78e5406266c66592
57
2019-12-11 12:11:39
0
470e8074014213c2e26408e0dd90c45bfec9493160de19f7cea2adab7c0e7d03
57
2019-12-11 12:09:10
0
3c75a5f6643095d010cb67baf764a91ed54c0a7648f59dd4321e5710ded0b7fe
56
2019-12-11 12:00:09
0
fc292e160153c23d073dc5e640bb26c5f2a4af4ab9d76e32f61238e3d62bfba3
58
2019-12-11 10:07:07
0

Rule Matches per Month (last 24 months)