HKTL_Gost_Tunnel_May22

Rule Info

Name
HKTL_Gost_Tunnel_May22
Description
Detects GOST tunneling tool
Date
2022-05-04
Score
70
Tags
['FILE', 'EXE', 'HKTL', 'T1071']
Minimum Yara
1.7
Author
Paul Hager
Av Ratio
9.09
Rule Hash
203bcb1b55462367aa7120c3c270ca63
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
13
Suspicious (< 10 engines)
29
Clean (0 engines)
12

Rule Matches

Hash
Total
Timestamp
Positives
VT
63d44e3dbf01f79d66b1662e9a98726ecbcfc461b999595723d68680ec3364a6
62
2022-08-17 10:52:44
3
abecf31d17fb9eb408924d6a7cadc9d2c2f10533dfb51cd4573ff5f2dfe2d518
60
2022-08-17 10:52:44
1
73d4a7242908b6676f8189695788384fbfe4c15ca026158a81c9e374ccfbe477
70
2022-08-16 20:28:22
2
1524f09568f946d74693abf6d03f44911f9a894f3f16088cc631f5a018fc0d29
69
2022-08-15 18:08:09
1
912a237c20c782a8f0d5bc780a1053a75f36413f8d84b73dd1dee9473db2a170
63
2022-08-15 14:52:00
3
e6900cd1199da792140a9e4dbd72904f3e199baa8167e95f802a8dd37e19f323
70
2022-08-13 23:52:31
9
9698cd5404d069d094ebde4725918afaffaaf8bacbdf2bfadbb4491f5358e942
70
2022-08-12 11:52:05
14
e66e70ca4493e0dd2d2dacbd043e8158516cbff366aea5a10d4ff2a63713d6ba
68
2022-08-11 16:52:12
12
7f6347070e0c5b9dad48eda3aa77ab6f75b3aa4a784a82f7cc9dc799e2f22aa9
71
2022-08-11 07:50:17
14
ee7b94532c0c14f9d7304dc3e37f07da523c3d1fec04109e1b71a72f8b189d5f
61
2022-08-11 03:55:56
0
e555e3f25a2c1331d168434c1e11fb2e48185657d34d129d42722db57f3ee1be
69
2022-08-09 22:13:38
5
4c235f2e0432c14541171b6fd3f364f2a0ac45efc143e48dd85f401fe7fa391f
58
2022-08-09 17:42:31
0
27ab01119cb82d2feb023d2dfa145e0b1c106c5cdecb111070312f211cd93af4
61
2022-08-09 17:42:31
0
97d526f541cdb17826f583024219cd680c1ff51af71b22ef2e9c09c48767c5a1
61
2022-08-09 12:50:39
3
9d931364f24a2c252622d2918df323910932be1a2f3115ecd1a4007d9685c503
70
2022-08-09 12:09:59
15
1d56151bca8b4d0e58b896f11d7b477a51bb3255e72921b91c583d357ffd051e
70
2022-08-08 21:35:03
2
1ec057cbef2f5dfccebbb4c3da946411ef54bd1316780a21be47b51a4ab160ba
70
2022-08-08 20:26:04
9
3a6691932da3ae4371254f55e9b576f66c8a6f8a3c2a2df91706d77f2be218a8
63
2022-08-08 18:56:33
2
6f9adc453b894b7932a9cf769a98b5115ffcbea145a903a677891ef01e97aebc
63
2022-08-08 18:53:17
2
27b8fe8dbeb60d21368767cd4a68f89e4dfddec3e2fde655b2b6c70ceb44d5fa
71
2022-08-06 01:35:36
12
796f2a9f3448a52f02c0a2b20c0a2aae43cac33ee640ef2b53143777c9aac4f8
68
2022-08-02 23:05:30
12
353bc66e7967a37aa6971344568a90f1b856b684cde69551ceb38dc183f72642
58
2022-08-01 13:36:40
0
9b0de67286652abe4822d30d1f8f03b84c2b5e7e801bfe6720628f3bdf9f2051
70
2022-07-31 14:51:20
0
f0868fbaff9d7cc3e4ec8a1515ef932752e4fe0325e6d5b82dc5597008bd3fb9
63
2022-07-31 14:06:51
5
aa5a02ab6104950553796981c14d8c22c2451692d07f04ae1c0135dc9b05ebb7
61
2022-07-31 11:59:57
0
8d237f8a818ca59b35ec6faf6ceff7ae82ffad3240ec0de0938b5b3d9012fff0
61
2022-07-31 11:58:55
2
59092b95701dd966d0de1d7f4e42422122be37f1b8f74e3e38537008ca5458fd
70
2022-07-28 18:02:48
3
2733045ba0cfbe52c9c4e133c25cfe3786404d4802115b525195b1b34aa9851d
62
2022-07-26 19:05:54
3
8e1bc54eee7d6736dd00f884d3797ef745f62bc00d8ba8a4d2c4ff8d8ff4f733
70
2022-07-26 16:33:32
13
74d5e838cabb4117a207f5c292ec99c02529f61a4eb75c76b736ab560a7c4d05
62
2022-07-26 04:49:24
1
3fb00ebebff222a8b22c952b6b5a0ee65d9374ba90f27b372c24d2620cc0c043
62
2022-07-25 04:51:26
2
9d97a249898d0a2a4279273e2a59bdc67d50d65ed2ca303315aa5ee83da9bb9e
62
2022-07-25 04:51:26
2
ffa99a7796cc014b4591676ed12f3c374cd94a1165e478bd4edbda4ad7de97d2
59
2022-07-19 17:26:51
0
e2482a8199024dc7d9eb34b2ba110872818b3eb8262b65b94b1580c7f59d53f4
69
2022-07-19 02:28:50
5
9ac7061110fe67376887b6ecd100305c5b2e2963c5aa56cd4350e64ff9741868
69
2022-07-19 02:27:46
5
21d7867c1ec48e5d058d84e3d51c4b0c4b840b808edc7c2ccbb8a719163516be
60
2022-07-18 22:33:26
0
d91e330f6954129c62611ba7d1fb692d51699382f506ae5ac5133a2046a3f6a3
60
2022-07-18 22:33:24
0
a7cec6367b107f2cfd190850b8e10f2ca2c3cf5ed1be4c951d80520a85fa9823
59
2022-07-18 14:58:36
0
601046b7fa0d6cdfcf2e070ef75d39a01e47c5a487527b45dd6f33fe06211db4
69
2022-07-15 15:50:54
2
e48a3f2df74a0fb88839e45f1364ec38ca6390efc3bfee41b17c17b892aa9914
69
2022-07-14 04:58:48
1
2dab6ac18eaa45682c6c65bc273d8132656533fad8580f90e2ecc16165de02e5
59
2022-07-12 05:38:26
0
9a564ca9e477dad8be5b38f7d02c5c845f78d8aecbb9b7ef19d8cca057a05091
68
2022-07-10 11:42:09
11
100cf2d03e18d886247c5c66afefd3f9e8d3d1fb84f17e64cc1d0348d9e2b933
68
2022-07-08 09:05:34
39
8dd1031a08b3a1732857c9df96b175552315130bbfa9aaf0a9b4f665f68f31e0
69
2022-07-08 09:04:18
28
2a6b0cdc76475c0ac4c1d76b31d590018be401f90f29c8a3cb7d033429780926
69
2022-07-08 09:02:00
32
7ac0a68c74196954a87114707c6baab37e51fc29d357a3e8d778d83e8b291726
60
2022-07-08 03:42:53
2
10cf688a14cb87a418d203cadb9757868e6639b3fa3a8fbaa9204035d5bce6ca
68
2022-07-06 22:29:22
5
84f454367bc34a95ec9573836b8986e6cee64a141708bc821e435a4df9887282
68
2022-07-06 12:34:18
23
d7b0614985e40f8113cfa67ee57be6b77c318d612709984a4de12c2716a2794d
59
2022-07-05 22:58:55
2
5e0f28bd2d49b73e96a87f5c20283ebe030f4bb39b3107d4d68015dce862991d
67
2022-07-05 18:18:52
19
fc84b1504d4bdd06401fe0d02c43301be5fb85c880cba21da8870a62c5f0db41
54
2022-07-04 19:55:03
1
1f0f654829c46b035b19a9fc73e558bdf75aa446155a7ca6943fc3a476bf586f
68
2022-07-04 16:21:06
6
42d68c3fb60cb4f98b9ec1b857cbc8632963336927da3aa6de99a93493703a6d
68
2022-07-04 04:16:02
1
3149bd42d485e527c66556a2ffa27d838280e45505320b99b0d72eeacc4c593c
68
2022-07-03 15:05:57
0

Rule Matches per Month (last 24 months)