HKTL_LNX_LibProcessHider_Jan22_1

Rule Info

Name
HKTL_LNX_LibProcessHider_Jan22_1
Author
Florian Roth
Description
Detects use of libprocesshider.so
Score
85
Date
2022-01-03
Minimum Yara
1.7
Rule Hash
36517e91cac42ce40e07cdea8d80b655
Tags
['HKTL', 'LINUX']
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
94
Suspicious (< 10 engines)
60
Clean (0 engines)
12

Rule Matches

Timestamp
Positives
Total
Hash
VT
2024-04-20 21:06:24
40
70
00c7d4c971f4bd023e27fccf8692bf6f2aeddc3a3b481f8cbf99100627fee40d
2024-04-20 07:06:48
40
70
99ad109e8ef3fca7682823ac6ff1b92ab48234676a938fdad025e7245d89c633
2024-04-19 03:02:57
37
69
3e3771420cc3e2ae87ac14183bebfcd5c87eb577036e4964dc40f569ce420ef7
2024-04-18 08:13:41
43
70
dddd079b0e67ef7e90724c746d76f742020fbc61ce2ea902f28129fa9ac3c146
2024-04-17 13:06:54
33
71
3daed104d38b1f88c18dc8ef9b07999e7f41d35cf8444a091941268b1653cf23
2024-04-17 10:12:31
37
71
1db15dbaecc9cc557d2dce39df4d5a1873bcde2f483d6414d2f9e6498b4f3a94
2024-04-07 20:06:12
19
60
fa5d68853dc1001c1cf063d80f41f49c604585128e66cd84d7627238ac70b391
2024-03-31 21:05:16
30
72
e8559eb3a872000431d00332b597eca6f4de35f2276b23960dcd7c29c080981f
2024-03-31 21:01:57
30
71
7e40e5658350c04599213d2fa5027546ade7e04fbeddfb2b6c9fc3488f6502d9
2024-03-25 15:39:32
30
72
a5be09ab4a73ab5c553e1e4fe0cfdb21d1070b6e31fadfb26bf015454411070f
2024-03-25 06:28:28
25
72
f716b7f779e426f8e55ca08b78547175ca40f7c6369758d40cde37c0c540b5b1
2024-03-19 10:12:51
14
60
f8c3ce7ff85978587a6a08b5847fc468bf4b81852aa5d744b9767d3b5e3ba9a6
2024-03-16 20:01:32
35
73
25ba71d062def2d4f6ba224f112976b7aed0ae73cb87aa4d666133af77a90ad1
2024-03-13 15:05:52
32
59
9300f1aa56a73887d05672bfb9862bd786230142c949732c208e5e019d14f83a
2024-03-13 15:01:11
30
56
2f603054dda69c2ac1e49c916ea4a4b1ae6961ec3c01d65f16929d445a564355
2024-03-08 12:04:57
2
60
74da05333c5b452e33e50a265182c10b985fad5c8da12a4f97e95da6a1d3597f
2024-02-23 08:06:39
24
60
ad5742cbbda37cb5e456f98ab69b1849ef584a9773dc8a1d6bf302659d9bd040
2024-02-20 14:08:01
34
72
55dc0c2dbf079c29bf0adcb89e1c001366fb08e2e58ac9d510f6eceeacb18717
2024-02-01 15:09:43
1
60
42d4db94cd6fb2280828f9abeee14ed351a7087b0fed26a6410c98de87eeb826
2024-02-01 15:05:16
2
59
f1fe868da9d90abd470d19ac5242af594664f0e9b9747af83ae32baace367b9d
2024-02-01 02:10:53
1
60
3d03bfffdcf917f58b0d7573666e1ae2d41d8ff4f0008d063d2837ee9cf50df7
2024-01-23 19:33:12
21
59
e26d12d30f1b6a41e9b15c55b9c3a8d7530e03aa57bf2e8b4d8f9513609ea9d7
2024-01-16 22:43:02
21
58
467d9e39c215c3e5910fe0fb262b54b68ec14209aa993b7924805969a4cb5307
2024-01-16 17:37:45
20
57
274b0126466042368cbd5c3a017864e8ade3233ac9b6976bd87e0187b68a0c99
2024-01-16 15:25:04
3
58
eae3d5ffb56bb8109c8d531ef2c137a0eac265e79543e73993f438b5e4b53dd8
2024-01-16 01:15:53
21
58
69d909517b041e9cd790d8543ea63d795aad395772e041d0529042af6016bb39
2024-01-13 17:39:07
20
57
4057ef7802913ee161dca59fef1faeca61354717881ae0910a535c2495e8ce61
2024-01-10 03:01:31
20
57
94658397ced146c2dcf2bdc2335ea5e82503a8910b744da85478d27aaa4e863c
2024-01-09 08:21:52
14
58
a8e23531feefd830da02d55f4991e611d678260ae204c47def0d8a07e57fc1cd
2024-01-02 17:22:30
3
63
3bb3e822b92c26a15d4206cc733a0ef26603898fecd26845390ab716712fc863
2023-12-28 00:12:24
51
72
4480493de4ac37e27db14a317f427207d51aeeaa1e41680b2726625675fef1b6
2023-12-20 07:17:22
13
60
64d8f887e33781bb814eaefa98dd64368da9a8d38bd9da4a76f04a23b6eb9de5
2023-12-17 01:21:18
26
72
1794a9573fa0a4156bc37d477b3e5af1baa1b03deb7098e861f56c02c88dac3f
2023-12-15 22:44:33
14
60
3f9f081d08af66f948eb44c147fb53c0f294af3ee264e8a6268adbd2e76d589a
2023-12-05 11:03:25
16
60
0d4e2ae8b7bdd04552e6e41c906d84a7fae09445f7c58a18ea35dee1c55e54df
2023-11-28 20:55:35
15
60
9a10cb26a686dd176d2ae5e7ec717c3581bb2605906a398adbb0fb6c42b88a78
2023-11-21 15:54:35
46
71
881d0fa3628f16e48fbc6ef3142696835e38b14c3e81c448b34b4e6ee35241e3
2023-11-21 15:45:08
10
48
6a2de1462b6877634782f710fb15e83c66b602b755e533dc2a87ea61061f53eb
2023-11-11 05:20:36
37
62
0d7b955b9b1b95f3871e7259a806d085447363369259e2da94f4eca7616b8e53
2023-11-11 05:20:34
37
62
d63f3fe1c90748378f39190368edd11ce14b11cc8d97304a7d9fdb09e77b007e
2023-11-10 03:36:02
15
60
e781db2c38dae419b67e8f73107c77d03b40051b28edc6a12b493d61dbacd557
2023-11-01 10:11:24
32
59
232c771f38da79d5b8f7c6c57ddb4f7a8d6d44f8bca41be4407ed4923096c700
2023-09-10 21:16:46
14
59
cdf508df820db85f8fed0345d9501911d9a1ea76f8ad08b4eaec4c7c7a825211
2023-09-02 12:22:34
26
69
df782d1412a016ad8764ef0284a188c92063c606d9012e91afa9ded319790210
2023-08-31 16:41:24
8
63
44d3109fd54917e2770c8b4c9b6819ea88e47c27013779bc28d05a676ecd7b28
2023-08-15 06:41:31
3
59
1e6b9e2755e2f683f6a9a469e3ca582ee6dc00296181ceba8ef9c44850e53c18
2023-08-04 18:44:00
29
59
aaef1dc83dbd07ce137debe76d0e26fdba359d0a98150bd5c2889a2b8f00e582
2023-07-26 10:23:19
10
59
5b53700a196c49d5b865b51e46b358a0ffd248bab4eee459a2f832cf1735e943
2023-07-26 10:20:00
12
59
11859b09f4ea3b8db96a5c51ce066035951709a232e253c00dd17f165672f1cd
2023-07-26 10:19:34
6
59
a58014626c9fc7eb0453b14aa53a8fe3e152fabed56e30bcbfba5fb945b26b9b
2023-07-19 11:41:35
24
70
1a32bcfc64e8f7771a2ff46d725dd8796120060d36067e8ff4d02dcba9c56b3c
2023-07-14 12:04:12
17
59
5aef92ccad5d6a4e3f134b441a051e0e6a01cc8d1d18cf5c8c5ea1b556874320
2023-06-29 23:37:30
31
70
c2ce1e1351f364e2d8f688f83f75afca21a3c5664b678f0c77d7296ba2e16387
2023-06-13 10:04:05
15
59
3fc1ee1f053250ebd9ceb7249a40c6a071ccf292b7fad5203fc6255916ff594b
2023-06-13 04:22:03
39
71
82d74e2c6f6f5e6cd82a7068de6e68cdf8f054a2bb0c122508e7873d9305ba32
2023-06-04 15:06:25
37
71
c1d2c16a045b23f120d942097db59acf6cf497bdbace969a709c1e365d4ab794
2023-05-28 02:12:13
0
59
568f3ef888229a675605943dbeacfb034d4c8d2219eb44ae9bfd094caed669f4
2023-05-08 12:14:52
3
61
fc41ea0426e57edf6a8001804091b723266b65fbd557353ef790109a847a6d52
2023-04-25 10:10:35
0
58
2320499610b4fcd57553964d91832069d7696e99ba8fc8f9db97f8fd16088339
2023-04-25 05:11:15
4
59
1cb10076c4d5b6bbcb67cf7cd406bae84bdadb76c38428629cf60dd6d524a55b
2023-04-16 14:18:22
13
59
afd91b04d381f79fd5a19c65c84a73de47e3ffefec8a263d3c8162d742ea7a9f
2023-04-12 12:13:48
4
58
eee24a16db4d6f33d08988f9ee6836d4f9d2cbe64e6718f1f5344a616f85e5d1
2023-04-12 12:13:11
4
59
e9c17aff7b1dc7222bc5b7a172c391672ed7a4f293f86024bb32f3001c025b5b
2023-04-12 12:11:03
4
59
4a9fcbcca09f1825f1cba794904643c97462e9c8b5fd7625b1a96a3d675fbe0a
2023-04-12 12:09:43
4
59
2b8e973fc05cb43ff651fe48c32a0635c5fa99a6481927175f90a22925100c30
2023-04-12 01:07:12
8
52
6b641a4435361cc444e0e2345b33813ffff0ac41f08a266b75ebaabbf2a67407
2023-04-11 17:07:49
20
58
fe3bc0ed48ad839c5ab29269303e8d13f2238350dc3052bb45af9834e3223ce1
2023-04-01 09:45:21
2
59
68f993793dd10fd173e164e2f7e46485be1592f6be4f779eaa686d3dc553b970
2023-04-01 09:39:31
2
59
ff63975869cb44ce38c6dca0dc8fc1b577251828adb64a634c54f3465add093e
2023-03-29 00:23:50
16
59
03692346c514c9355b9abba63173e59d4330365a64f2fae0d6f3561e232f4b0b
2023-03-29 00:19:57
20
58
85ee43e01a574d889fd45a4f016895e7303d5213ec0ac2d05af5aaab76c9fb24
2023-03-21 08:15:54
13
59
16c03a6aaa9d2d8747a73d4b6d0f8b983f9bb64612cec492439229f9ed984042
2023-03-11 02:11:51
15
58
d5b77bd96a04edc59c9785a210529064c8cadc2ec271ee2ee7273065344b65fd
2023-03-11 00:22:48
27
59
ab07c963741a565d6ae4b394ce7aac7685ef5e411c3fcc1403ba08a26854b77d
2023-03-11 00:20:01
8
59
9ae6fba4d9359a85984377dc9795de422bd9fbfa41558372ba8be9d5b9c9aa14
2023-03-09 21:16:28
26
59
85aaf7a95b073208b70edfb931592d45e6f2f3b314b4fa9dd0ad4ff6818d725c
2023-03-09 21:14:50
33
58
879dfe253609611b4751ce761548b62c8a686c38b761652fe049ca62bf27d99c
2023-03-09 20:35:09
22
46
7ed8fc4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6
2023-03-09 20:33:20
28
59
7e9cb7612809c8412085cf231710fa425e5a8046525e8ea5a0e56aa78743ac83
2023-03-09 20:33:02
30
58
7ea112aadebb46399a05b2f7cc258fea02f55cf2ae5257b331031448f15beb8f
2023-03-08 21:11:18
31
59
2cc6dfeaebdbb2e35f9c8eb158929063655bc4e2fd4f2c3c02dbdf29dd721649
2023-03-07 19:43:16
13
59
bcb7038e32def722d56d9b1f6ee5eeece60513521bf7ea004f7cff035ce679aa
2023-03-05 21:32:41
23
58
0c1b10c1617f5ab19b74ecbb698a506620381f63337132b998ba7cfe08aa30b2
2023-03-05 21:18:03
19
58
082e0a5c67357a13b6342a353b0d376eeddb66f26217901ead563d0c724b6079
2023-03-05 21:04:41
9
59
0405e55d8d935d026171ac1cd5b7537f15db47e90efbfa12a542ca884a5e694b
2023-03-05 15:55:24
4
62
12a38fa634e65fec87ae766d47f81ef20a772288a03951fa7c4da3673da5d55d
2023-03-04 11:27:47
37
70
68a91b593cab6aadab79c477d8aa4462bcc9acec6f6df8fe1c864129e61eed0c
2023-03-04 08:24:53
37
70
72436826c286f1554e9cb4e95b84859c3257ececc860f8f0368a2e539d1ee108
2023-03-04 08:23:44
34
68
bd18fd9926a85d54e7e41c2789b8bc773dd7e85f403adbd4235cc0c3c5279385
2023-02-28 05:40:41
16
59
9dd935a3541cfaf973517b298383f8f110d464422ddbdf417b15f0d29c992ace
2023-02-20 14:20:51
1
60
fbe52200264043b2a2bbcb84879ba44374fa04a19bf7aa17266b7226b5fb70e8
2023-02-11 15:13:28
26
60
596e6ffb99cc6103a93026eb9b4cf5ed6234522f961c42d021ab93f57439ba35
2023-02-08 21:47:36
31
59
be4631b2ac96d0268d87c21b8749a77d2d711200b43a0623d2c86b24c1c464df
2023-02-08 10:01:10
25
60
fe6731f3025775e97d97e08699c57f464112883617bc4505cd8912ac7379d34e
2023-02-06 16:49:24
1
60
4229c4b89f2f0d43626e65946b68f747c047140c8b7efef1b0b47f64c98ed1c3
2023-01-20 12:18:53
17
60
e50b9523198698645fac1d647521dc47d9d16dfbbe32d71839f27d7a0761b626
2023-01-03 13:40:30
36
71
82323e5e8873261d7ca1c8bad98149c48d024285af7a9f9e734c6b6fe2808e90
2023-01-03 13:24:11
36
71
b92dc9faa4a99ea24321442e7f338172e94385ae3edd053f365d5015f7b03cbe
2022-12-29 09:21:23
25
70
9f89f64a9fa76c2a64fe9304dffb8feb751463d780d23567fad7c8a55f6bb737
2022-12-29 09:07:29
26
70
a50df2957633633c6c2c7566ba13f3c522dc8fc2ffcfc52bc75ce25095c9def1
2022-12-16 14:47:51
16
61
eb044f8d8f404483db9a4f43c1ed0ad1c539bd807c60fe19e7787d7cda85a45f
2022-11-27 09:08:12
10
60
d92af4197127e5a03d34785ca73422e2d519e853e6c829cc73bbb27e95bfcd70
2022-11-20 10:35:04
36
61
80957ab41c7c9394f083d2c154d75af32615e4e96931b1ee4abb5d0a023b3ce6
2022-11-15 06:36:38
1
61
5908edc07ec67ddb6d0a284fcae8d368cd9170f48760ec1a4d53db95692114c3
2022-11-04 09:17:19
14
61
42e03179318a2a0f8ab262783b0ed69b5946a994f18b6f531252bea68e17030c
2022-10-26 07:52:18
13
61
caa625006b36ec0ebed55c93ba4e6548627ad472bde849069e6f0206fa084046
2022-10-20 23:00:56
12
60
1d34f7826010b37f2a788b018e3e94c091c95b155a07517d7f5aac42182c5129
2022-10-19 23:28:20
12
61
84c77600a8802b4094b51e4d52b19d5d964c36fba56bd26bb9a52596bd50797f
2022-10-04 10:16:21
12
60
7970bc384f0d4b9ac8460d8340faa9770260dd9c13127682fff3083b2a521a7f
2022-09-15 00:19:35
22
60
74f647df6d65ce6a8f6cf0c14a2557bdf9a0ea9a50d2e0b1285bfcacb640346c
2022-09-07 02:10:05
32
60
ed038e9ea922af9f0bf5e8be42b394650fa808982d5d555e6c50c715ff2cca0c
2022-09-06 07:24:57
12
60
e3c5646531a09c223ec5cb89737c35213b648de51a9782f95d213f9ac910af72
2022-09-04 21:09:48
45
71
fce0fe4ba5f590ab0c0f2db9e569a6d5c31188897b7ca58cb21fdd9ceb1f32f2
2022-08-30 12:26:22
0
58
0b71926ff280913fc51dd411f45099ba67efa7ab2d7dc5c27bad3a40647fe98b
2022-08-30 12:20:35
2
58
16940bda0239f1185d41c0a4e04bf6eb6d4f2852f6e82e11a243c04cee45d75c
2022-08-30 10:40:05
15
59
03ba0953cac3978e9db7daeab10a447bfb96f61b9e0273ffdcb3e606ffa0bd74
2022-08-22 18:17:35
33
60
71f578d122252c7fa67ca343cd29d65ac42d6f7c45bf91f146a1cd04b0446c23
2022-08-20 12:07:32
7
60
cc25059e0b05f58d81eb91bfd988097a76a0ba5fa0cddebd3a1dcd862a6b373f
2022-06-17 07:51:16
0
58
5542fa9402cd204d7404c156759c65ca3883908dca7342889555f2561266a82f
2022-06-13 13:17:26
0
58
41fe66c629a7d097a981d9b21089f1b9d85eddee0ab4411a6292e1461fb7f733
2022-06-09 19:16:15
1
56
cd3af91026fc50c0f612160bfd7b380d54aa61974267909432b3c5c095637c77
2022-05-20 14:58:27
2
58
e353f1c2e91eba1f54cb2121da97135fa0bfc8c103bf07a94fffb9c6c4ab2088
2022-05-19 06:34:25
2
59
8270d67481230009386512858728360ecbe5635ea960972ca1e29e65c0a9f64b
2022-05-19 06:28:58
2
59
95fa2fa46f4440dff33b124fa830966d30a10d352d79f6b16248516bd0cf2c01
2022-05-19 06:06:38
2
59
b6fdd287e38dd327bce0587879efa067c0d73a10d8b3382e7fc3174f7bc034b4
2022-05-19 06:04:31
2
59
58b99d883ef20c7c44b799d86eb9d4f14df796638c13af38cc2e2b0c5f845604
2022-05-19 05:11:09
2
58
6aa7e2639c6df0c7c88edce11c046896c9a5f6e96883610668c7bb8f690a2ec8
2022-05-19 05:06:20
0
52
af64f2d67b5c0084d90f6b3d6c9360a37ff03a80b619d5cf1cc6f68f546396e5
2022-05-19 04:47:22
2
59
9b35c4d5f55eb420f5ad4ee9a9cd5d4bcde0710dc482facbe737aa08023e0ca5
2022-05-19 04:39:27
0
55
047534c33c7bfd4fdfcb699e557a78225b32ee1ccb2aa71800ec74b17b82314a
2022-05-19 04:29:12
2
59
de19a1f162ea46486b33b5c82c26f3c82052a3e25027d9c47469ad2d66321643
2022-05-19 04:07:58
2
59
870c3f3e25e102d9bdcc072500400087c0b29ed5657880a88df43ac6377f3e49
2022-05-19 03:20:11
2
58
b72ee3e1633e140a096a30e2fac9fadb424691faff8dc78aff57b0a863bba593
2022-05-19 03:15:07
2
59
539ca1d0e147f584a04f41061f245a01e1c9a5aa46963e376d585d264913d41f
2022-05-19 03:11:08
2
59
312ef4910c5fe6f4b1d27b431070d7ae221b087df09de7c1abb448590bdc3a65
2022-05-19 03:09:13
2
59
99daff4d1aa8232f39ee2c514ef62a04c10b20c718ecb169bbc9705817b7bf72
2022-05-19 02:15:28
2
59
32b1efc7b708312f384a57a480ca8804d530495a672eb2c5c123b67c5d9bcc01
2022-05-19 01:55:13
2
59
1298c7e2fd9767b6ede4be028897919a365db7833cafad5de564473134700288
2022-05-15 10:20:16
2
58
a26ceea7076fa48ec46228af9d1ac3f7c57df142fc2ab378f039128a2dbe075f
2022-05-15 09:48:13
2
59
ee4c9621e439ab18ee38418a4fc86377298dfdf7106a2990fac906006b68856c
2022-05-15 09:47:10
2
59
881ba8b57fa9678ee090808c63f6354f755837af06788941bee425e640873c24
2022-05-15 09:29:55
2
59
d6fb60d125956d9af33c106ec8576b1ce493417d98901e12cc16af313982e64d
2022-04-26 17:20:50
3
59
1abdfc2be5f1eab33977fe9b548375baaa64745a577ed348de5ea5a247eeb1db
2022-04-20 13:08:28
3
59
53324475a0f4fdee70f662a255edd5075f8d1c081bd782425845b0c6054e2d4e
2022-04-17 05:45:46
3
59
d19421c0d480d422089cccc83a84acf5fb5aa02772be7644955a20b8c8ce49da
2022-04-07 12:06:01
2
58
a126e143a8f0c084783678981046b2613f39bf738b8a9564b1214237f880cdec
2022-04-06 07:24:14
2
58
c1349bf7b543bd3f05e8bb8fc869d924113864bb382062fab862deb311e4589b
2022-04-06 07:10:01
2
58
89a7277de46043b8823452f449e394bbd954813f20dab7c258d0f2ca2da3e384
2022-04-06 06:25:57
2
58
5fd9756622b1698310e2ce2430c76105dc326a2f54278d016768de14a107ca90
2022-04-03 17:06:34
1
49
113e6bc75ece0013a1912c01a5f3f7e8a04d1b6942ffb7363a29748d1dca730e
2022-04-03 07:43:48
2
58
f7600f59869df49685f8a9cf2a5a0f49961fce75b01e2a03dee02b6868a6722d
2022-04-03 06:30:49
2
53
9eeaf530ab42456b53e9dad3315ce5ec2f8bf96a4bdbf26c733f3f5e84c1046b
2022-04-03 06:26:18
2
55
3d62d4fe908b5c5a3267efdaccb621f72e15711e3a0aa07c8906a64ad3c5053e
2022-04-03 06:20:32
2
56
7037da3b4e5f4b9009c6940c5ef5ac0cbe7e62af9511f127328880bf56722933
2022-03-31 13:15:03
32
70
c3338561f1c89783019a15c551b5691bfd84df49b39d283cf26966ac6f017013
2022-03-30 04:45:01
0
57
072fd60d4264f9aa576f48981a4ee075cb141db165ba72b57409f44960650f39
2022-03-25 06:55:58
2
55
aec99e36b6ffe1fd84e4a74d76ce6ab18cd7a92cee8f665087cd7b55b504b33e
2022-03-22 11:02:17
0
56
b8065283749d9a5c44fd54a404b14a04173804cad7e38beb8d33a451f9aba929
2022-03-21 08:01:31
0
56
ae8159d5e0dbd0576d195201ea637880b9aa4ce9891e512053402f7fd6d6f32c
2022-03-16 03:27:08
30
67
47c00a6ec77142336febc3adf3dce1c53ba113eb4fa6a2ccf80a1b323e5ef82b
2022-03-13 07:21:32
1
55
0f02b83a789e9933cf04b5e0e493ff3eba9fcb2bf521159685891cb88f273228
2022-03-11 09:14:15
12
55
1a09f706d78f46035b570c85aaf2ea48edea5130c58b78dacc673c88227f6478
2022-03-11 09:07:40
11
55
53047c6f255ceee5ec989d73a36fa97ac6035325ea1a81e959b585220188fd11
2022-02-02 08:37:55
34
59
e1a3ff46a99f4fd93d99b0e61fe4ddef8f894c2a69490d71cb34ab10e4afc0d2
2022-01-26 09:38:00
0
61
fa24cf3f9eefc4e8d64078d2bd9b749eee4dd3e63338db0b5ec181f9f3ad7111
2022-01-24 02:23:04
0
61
451ca4a1293d082377f07b7434ec4c2d2bd45e2040669275e42d3502f697dd61

Rule Matches per Month (last 24 months)