HKTL_Merlin_C2_Agent_Mar22_1

Rule Info

Name
HKTL_Merlin_C2_Agent_Mar22_1
Description
Detects Go based Merlin C2 implants
Date
2022-03-28
Score
80
Tags
['FILE', 'EXE', 'HKTL']
Minimum Yara
1.7
Author
Florian Roth
Av Ratio
8.4
Rule Hash
a5c5816da1bde05dc4de5cc990354bf5
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
19
Suspicious (< 10 engines)
20
Clean (0 engines)
33

Rule Matches

Hash
Total
Timestamp
Positives
VT
fcae23243271cf722ad3dd97347aadb7f4f0e3d453583e2844f2e94e4e36df64
70
2022-08-16 19:03:08
3
8647157e27cd951b5dd2652d3eb853ffa22f4eee902fffd7a9019c6ca86f2b1a
70
2022-08-16 18:44:23
3
9e5da8bf48c956c2ac523ebb430ff1712952c6309b74526a49258ce67b18aab5
70
2022-08-16 18:11:02
3
bdd7ab17911c0df077866cd69fefee317b6ce7f3b9999cbbd92a1f25782bf088
70
2022-08-12 13:51:53
8
3ba7ba5327c0802eee855a3800d962fe3df3165898615ff1176b114bada2d5ae
71
2022-08-10 17:52:18
8
e5ea58508471fcb8c0977f5961d2a241a67959843d98df21a8ae1fa83be83a8d
69
2022-08-10 11:05:09
0
aaef1feb06afd676cf9054f2e94d036b1e4398ef94e46d53009a33b86ff47d4a
70
2022-08-10 10:28:47
0
ec56aee210703612044067cd027403247ab9d1b7fcd33167a237479b697bef71
71
2022-08-09 13:42:55
6
73d12b406b5dba79fdfd3d028ea545c3b9d027efe8c2241cb006373e334e9e97
70
2022-07-26 11:44:31
9
fee4edba099d3c1b0ec6e7939ac76d06ec521ed5c397a29b81432aaf125cd353
69
2022-07-15 07:18:31
18
7ec6c207e803201f464582ba3509af54a6986d57d48be737157249ac6779ddad
69
2022-07-14 17:41:55
3
57575360027e5c4c6314e15dae0a7e5cc0baf0945df8ed43b58047b618de7e5a
69
2022-07-14 17:40:51
10
fe63ae0f2e9419dc5a2752aa956e407d1b89caf7b6b00511c5d60b4dc6fd1f6c
68
2022-07-14 17:26:52
10
6d4baf4f242b1c8e390f592dea70d4970f071f25b78f2a14a2d3c3728b17eca1
69
2022-07-14 17:23:39
10
ba396d99ede0924b244ef33a279b44113dfad556207e760a86ada403b2e86c8b
69
2022-07-14 15:22:06
4
a545b464529ad3cdd87cf9237a30964cd1189a2c05f4e1716652d4c4604af053
69
2022-07-14 15:19:59
3
84aa8ca206fdf695d5d65310a444932b1b9a0314a0fb4604c53db06cedc275de
68
2022-07-11 15:51:40
0
cc8b4819eec97e94ac0cd80cc593a9755b4321bfe1c156d48459a832ff79f408
68
2022-07-11 15:29:59
0
b750a2b6e53eebe294bd4587a15e9ad86465800cc2ffccb62fc281cd9b1be10d
67
2022-07-11 13:37:17
0
a5b42f0c047ff4018dc77b06ed3bc6be0fab527cc524bd9aa908196060a0a18e
68
2022-07-06 17:26:34
0
e21b1b947c352fa78d7f0866f99457cf0a839993b5e57d178f55ac1e8d42a18a
61
2022-07-05 04:30:34
0
97ec0c9d34314c3452166ba5f4b68f3ae6c1bf6dd0f1d4ebaae9cde05a9e195d
60
2022-07-05 04:28:19
0
23409c602658da04d7719b78d6c018696cab1cfd0279e04081669785b00349b9
60
2022-07-05 04:02:16
0
bdeb4a8aac637f3da89ee9207d2a5497d040eb5627432ebca2290ba287da7b1e
61
2022-07-05 03:32:56
0
2782189c42e98643978e6182815b6f3b8f600a7330d621fee93f4a4cb2a98cf6
59
2022-07-04 09:18:46
0
01ee0c19a2e2e2f8239cd2b768256f4c271dce9d95d1c40976df8f96f8075630
68
2022-07-02 11:28:30
0
baab536122b0a402917a6051c94d73463a821cf3d74c2a66c9d5e2350ad88277
68
2022-07-01 22:09:18
0
b05fc8893804ce8fe86c5a1e0798e97e14a64f08d4c04695be3af5f77d64440b
68
2022-07-01 19:02:53
0
c9dd44ee0a8e652b606d626959b7cb59507949fb7f08b09f11b126aac0385d00
68
2022-07-01 12:22:53
0
9a42c76bd6f578b2a0e7482759802856ee2a564dddca3c3386638afe0afff7d5
67
2022-06-30 18:40:36
0
3e0ab639b2f098bbab1d45dc08be2b5b1583c8338c5fa636e5c8b67dfb38fb14
67
2022-06-30 17:37:22
0
e073cc0fb8aaffb633e21bc1108b280132ebf778b88ff671e44a5609d79b19f9
63
2022-06-29 20:19:57
0
7f5a7218237e4a0ad0f4862be797ed0e5953e7c627793922a082e2a76ef4ef57
67
2022-06-24 06:33:10
18
ac1d2b9e04cb869cf342895875c5237d2e667bac22edb21ba8642ee23b696126
67
2022-06-24 04:50:05
15
0fd521b08ebc57f6b215f4d8af44f5bc9e4cf7019a21a63d5bc1533404c19abe
65
2022-06-22 15:25:56
2
4968161f3a9808460a0fcf1ccaa651e893f7a4024f968c68f9759e2f0bbab166
64
2022-06-22 14:29:23
18
b3e4a667445d59268f6128bc94c053f2f0d04a02fbc517c14e96d801787f0765
66
2022-06-22 11:11:54
6
664b192bd65a9a6b82d3cafe3d8c296e6454df66654543db283f0d3c56a4e4ea
67
2022-06-22 11:08:36
6
b8d486f03f27c8248d195e12edd47f1c08d44ebadf45be42106d66798906b530
67
2022-06-15 10:32:43
9
3e98e4bc5eda08fda557938c21b5e8252fc5a37e9433e4b24987fe0fb43cd240
67
2022-06-10 11:49:56
0
af815b84b2a0a85ebbf1fc9141a59d9cfec2f182b4672fba773a5a143c32e768
67
2022-06-10 11:17:35
0
57dd1c061bd9e0eefa380eea2cf859cdd692438fd09786e425b7f19e6ba41337
67
2022-06-10 11:16:15
0
a0e488a2901af7b7782ee7705ee55a013036c97d7e957d05aad9e39a122f7742
67
2022-06-09 15:52:09
1
36ea8b2d9ba13df564af39506e72e99385b38c28580377fbbe05628ee195395d
66
2022-06-09 13:10:24
0
bb20709e2e11c5d2c82283b5a57cd667f32fd7ed176fff1ba4f6497c2f952959
65
2022-06-08 14:17:03
15
b8f5531e7e6d4284a71aa4015722f59b2fb2405ab3326fd0985257560a222d28
67
2022-06-07 18:29:39
6
c52a97dd899e56d44dfff71237e9953514f18786f43a7648db4358935aef22ae
67
2022-06-01 20:13:59
16
fcdf0aaff20638b24551358c56336553fe6a32f5a0f812abc1bfbfbeedb136c7
67
2022-06-01 20:07:45
3
f1bc6166d029dfb486bd61d0a9ee2fb13d2c0ac85d950bf10e01a09b2a77c8c0
67
2022-05-20 16:38:57
28
631fc8da17bc3eb84718969a48b679237165887baede146faba6df842c80ab5c
67
2022-04-19 17:19:36
1
7d58e7e18e2f059008c92c7ed5fd76c3cab2cb3475a3db458af552c2a944b90e
69
2022-04-15 11:48:51
19
3c023e946de058ce055634fdce4d0969601d957f3efb0d4d0f5812c8ec5588e9
68
2022-04-14 07:16:19
0
7887a1f838a2e013feaacd417ed6313732d1359e5b0c473a6ff957aba4694c9f
69
2022-04-13 18:38:00
1
adfebfe188e76fc19aed2e0f45c51c5768de567dc0f6dba891f9d99f022867db
60
2022-04-13 09:10:46
0
9058eff6a12a212f1f55bb4b49d0b64db6aecc3b06d4228003e65ed271f1e80d
69
2022-04-13 09:01:30
0
f9126b815eebeb359ffe49dbae8c84919efdb054c38a5f210854f81980f56d62
69
2022-04-13 09:00:20
0
5bcf5a94d5047e3a5b42a3b7f67791e0383e15d3da4a7b10b229941c2ad6a794
63
2022-04-13 08:01:08
0
5db0e230a859ba766554a224187911914a2de37e4e57d3bbff965780a4480332
69
2022-04-12 18:42:40
1
1589f838227f18819e00d00594ce79273a36a33d8420864477d5429917909741
69
2022-04-12 12:37:46
0
8cea0b27a0a3519237ace0fe8ab06b1e5c64bbd69817b6d7df0098fad96c8fd9
67
2022-04-08 12:48:18
0
a8368fac8251d94bf0a7b0c2fe2f5c2cad435fec345f1f72633ac97857356e22
68
2022-04-08 12:23:24
0
729f5b8e3303b21f769bb2a5a908722ac67be1c6b128ec8c96a5809819a2b751
67
2022-04-02 00:32:35
21
c6cdc04d62aec87bdebe44361d65d01779ad466d62edb45127c09f98239ff2c9
69
2022-04-01 17:49:17
0
01019589159d7b46e85fc19df3f6bb2043944134be9f25d3cfe85e948caa7314
69
2022-04-01 12:50:53
0
435f7677aee9490cc4adaf832893a6847b90987d62f7617a9e6b4668ca032c04
68
2022-04-01 12:50:47
0
b831e9372cc1f36b0ddc5ff672a24c29f4795b938da71db9f1313fa8e457b811
69
2022-03-31 11:34:09
17
aaef6acd0622dc3563fd65069e2946dda952e038d531d4853abcb6e409002ab2
69
2022-03-31 11:32:11
15
916db7d17dde88ceb9b5d73d6d2b8707ec52b44d614bcdcada15a413079812f5
70
2022-03-31 11:28:59
17
86fbd146cacc06d38ce0953374459c2c39364c2826b9a7d02ab545dadbc08dee
69
2022-03-31 11:21:38
18
35f94a4c8e00f1c02ef56e09d0727e24b4f8f8b9bc770451d751e317f6bb38d1
67
2022-03-31 11:11:53
20
3805e7586c04efcafb4d0582a6eca7bd84d06cd1aade593026ea821588acfb53
68
2022-03-31 11:10:16
16
27d82bb9b3c694d3c50652f586990c20920bbab9872ddfaed8eba2b0552dfe1b
69
2022-03-31 11:07:14
24

Rule Matches per Month (last 24 months)