HKTL_Nim_Shellcode_Loader_NimShellcodeFluctuation_Oct22

Rule Info

Name
HKTL_Nim_Shellcode_Loader_NimShellcodeFluctuation_Oct22
Author
Florian Roth
Description
Detects NimShellcodeFluctuation shell code loader
Score
80
Date
2022-10-10
Minimum Yara
3.5.0
Rule Hash
bb2d9658fd806cbcf5d6a236737a4cc6
Tags
['SCRIPT', 'HKTL']
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
5
Suspicious (< 10 engines)
0
Clean (0 engines)
1

Rule Matches

Timestamp
Positives
Total
Hash
VT
2025-05-12 18:54:28
0
63
160cd87163b55ab3f07f7b8316fb208fe0d79cd96e7c1ab7980a98faa3073acc
2025-04-01 01:19:00
19
73
06d5e5bd4ee258b02d0de4d1a6255beb2cffd5693f88fac09662b6b25c50fa1a
2025-03-29 18:30:59
22
74
c08af0b630d39a807b44b573fe9972af4a1ccb774bf8c842f548e8bd1407afdd
2025-03-29 16:55:12
18
74
ad44433d74920f6adaecdab1b1babd3bfb1d83d7088e9b36b33d04ca5085282d
2024-03-15 08:05:27
34
73
97c3d1df87022b1e416b7c844f386a91112747fd24ca690e35c828f5620183e1
2023-07-08 16:10:19
13
71
686f623ff05bae4a780b1ac4523d49dc8cd7634f7618179f121b3e9e7c74ed21

Rule Matches per Month (last 24 months)