MAL_PHP_Meterpreter_Jun20

Rule Info

Tags
['MAL', 'METASPLOIT', 'HKTL', 'FILE', 'EXE']
Name
MAL_PHP_Meterpreter_Jun20
Minimum Yara
1.7
Rule Hash
dab7db1ff0fdb0e1bac03e173b37d6a9
Av Ratio
18.2
Score
75
Author
Max Altgelt
Date
2020-06-25
Description
Detects a PHP Meterpreter sample converted into an Executable
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
21
Suspicious (< 10 engines)
37
Clean (0 engines)
0

Rule Matches

Hash
Timestamp
Total
Positives
VT
ca88814b0ff45c5fdf291244adec2cd4296ae8accb7ca30c871346a6566f496d
2021-05-31 10:32:08
69
6
81ebda893fa909c7611203377cfe024efe17c48fe8a8f5d1d0da5d3d15e6cdbd
2021-05-16 22:12:19
69
4
418cd132cd72cf838ae534a528afb5b81abefa4396453219d3502a2cb7c085a9
2021-05-15 17:54:41
69
13
6d4d3b667d7704f1138ac94c7723eb92be9f88b89bdc3b2cc868d33db36eca28
2021-04-25 19:53:32
69
5
90ee0d1e2ff176ebc095b6d299f58453e7b1d08b78e17f7f70aa76298e96b15b
2021-04-19 13:25:11
68
30
742d3d3d7b04a0ce5c16af46ff42b50caddffff2d45b874a5c2cb7e3c3916028
2021-04-06 12:09:47
69
13
4097fd4ce8d02fb3fb30609e019fb0216d53e9db45f3e49dd17bada2f49aeab4
2021-03-16 01:51:19
68
9
b51e0be8fae1d60b03c130e9740b39401e98e70462a6cef929c3ff7a15d59063
2021-03-14 02:18:08
70
40
61f8beeae250944e4516e14ff0e615ae05eeae6d746a89e5865226b42f410123
2021-03-12 05:50:30
69
31
9d1fa3ff380704f04e813ffb44a68f2a1214928803060299be7ec94cbf911b65
2021-03-11 07:08:56
69
7
3e629c20966ae5dbb2677683ed72f463993124acc9f90bb8427794f43ad9013a
2021-03-10 02:39:43
66
7
26ee6442182c50d9290d1f06167b4b08664ecfc726248d8328e69da2df1cd238
2021-03-02 04:32:14
69
10
63b7a3b648520c46d7f9beb060a7e96be517db3753811b3050128e2db1f805b7
2021-03-02 01:47:23
70
28
aea176b838aac76ca8da85cf8bd38db631340c6effb5037cb52769534f75b336
2021-03-01 08:39:46
70
10
c95e2da529d4bfa810aa3e608a9a6af9c9ffbd249598a1aa3bcc7a01d8a1d66a
2021-03-01 05:49:07
68
10
2d93f5b13d9bb29639a1d213aa7a11641bfd8ca151e14fed802cca38b8a88c0a
2021-02-26 11:00:22
70
4
2b20bf3891f48cb5a5295404e7fb7846674071c0eae3195cbf2fa24fed27ab6e
2021-02-17 21:56:35
70
6
1a2a7917cfb9ac81f7cbd74a74faeb7af0c4d2c2397d8ab3fa873c24dfad3750
2021-02-17 21:56:04
69
4
a509ec39d00623fae608e5481cfafcff2ecc5955cb483c7ea87a98ac8f599341
2021-02-17 21:56:03
70
7
c10b01930efdec82d4d5f630019235152bd2e2ed9444e8ff9056ef3d3f7d8ea2
2021-02-17 21:56:02
69
3
1c57abbf596b8d32a9536a90e50e37dfb5cbaff884032f0ce92a2e60aba56ad2
2021-02-17 21:56:02
70
4
e8622aef48b0d959969efcdeae555a49e136a5d7ccd5f6b4ff54afeba9aa90f8
2021-02-15 12:33:41
70
27
628fd9a3755b63a9881585731fb0f0010a9c2c8c25acec9786f00983188a7332
2021-02-14 13:12:43
70
5
e1f1d347e9c934a09d5cb7364a93db00a21740d85350d4b765fac5b281c0bf71
2021-02-08 08:35:21
71
21
df8b15f1d2f4d17236671e6a2e028afbb9b8b0e0d9232f1c6db03b3e78adcc0f
2021-02-05 13:16:37
69
47
3c7d6c9503560394624bdf5ad7ca209bdf7970511da6b50c20cfbabdbb646a92
2021-02-03 10:30:17
70
8
265a5ebc8fb4e19a6ac61b7670e50b66b3389be4a4d022bc28ce4d0428a4a885
2021-01-30 19:13:12
69
8
14e44d420aec2208966868951366e3240888a12e2d48c90c39db6336c1fec49d
2021-01-23 09:13:53
70
33
a34a025676c3550d2b785744a42da521b3bbe15a50b51bb0e1c49845e2a31271
2021-01-19 18:38:18
63
6
26920ca04744b9a5f0be3ec4827e4ca76296b538704f415f1781ce70e23ebbd6
2021-01-18 04:23:38
69
11
ec5bd889cdd70840a4ec0f78efab10b27acf84a5f4cd04af342766721b3aff1d
2021-01-10 04:59:24
64
3
86e9f032e53b4d695e4de4601b51c9dc695a06d59254c01bfff7fc882ffe1abc
2020-12-30 11:48:16
70
5
3d4098fe34cee87aef32ac26741c85a074d39327175395c9c6f36ab1ca887378
2020-12-24 12:55:33
68
5
242cc4f9e68e7a050d8b964c6fc795990f3887a88376322e3a49a248d162d793
2020-12-17 12:36:03
71
3
1ea0af49b4a0f9429f5570cf3bbc3ab3a9621a7196496693120ea2f48b30fb2d
2020-12-17 12:22:44
70
2
085ccf6acfaa1ddb2032f9a63769242edaf1c5f5c9a6f05d54f78432c027a480
2020-12-09 15:18:44
71
9
4939a8d9dc9487bfdad16608d37a7be4bd7222068a8512d0a15650a98fb0c069
2020-12-04 01:49:41
70
45
00cacba791eee98b3b508710a3fde1d867b639262d24007c7ca99b7116f4dd19
2020-12-02 03:59:05
71
7
aabc667a676ea3735841b7f71949383a943c43d9c42f12b35481915f17bbbb2c
2020-11-26 10:31:33
70
10
562243d6a22c96262041acbc4944b8b12f92eadcdd1b58ef3e0964a416cf7b0c
2020-11-24 12:27:53
71
31
af9992c51432ae4f6d37fdc57e04b2d5593c790d7303836ada2b91a1ce001d43
2020-11-23 15:59:34
70
15
55c56ac11e4550b42e9837ca6088c6b8bae7789dbf8493f7e525f3a1bc514ca8
2020-11-20 04:22:26
72
23
d7e29c580b3a58221fd0d167deeaffaa826c0290c27924ea0725e5c8aae4e407
2020-11-18 14:57:58
71
4
64b84246d2b1bb6ad3b6fd7ae4d9208e6acb125705dc342d32f25e02ed45522e
2020-11-18 13:34:52
70
29
2ee9d05fd61f1af0192e402782794b9bc2ab66d9ea87dffabbe4363e287718c9
2020-11-18 09:57:02
70
7
968191aca575bfb2ee3604d8ea0e5eec44e1a0e05fea1d669879780ff6f9c17a
2020-11-18 09:21:32
72
9
fe1c97c7ef2416708bc6c35af81b370677c60b4af7735c2411f9f0492e294456
2020-11-18 09:18:48
71
8
3fdeac3bf3d07c12e60b1a265e0f548c15dc1444c2201b02c7eaaeadf5ceec28
2020-11-18 09:15:14
71
8
2479b64c68b40b4c68042c41979b019ac2e3a1a53de561b012e54ce26e3bdaef
2020-11-18 08:43:23
72
8
d603b3bc6717dccdbb0be6a92797cc57f197d576ffed6e7dae45d84891512d7c
2020-11-18 08:20:43
70
9
0fc19f07eda60265466415df9d385e069ee0aa96b54cbacfeb41a4e3e04f46ef
2020-11-18 08:00:23
72
6
11166e9fe7a98b6e9f1145bc5071abe798bc8574f5ed69792e71181f3d681511
2020-11-18 07:59:18
71
6
9430bda529dccc4802bef41bcb8306258bcbb8e6491ed68c7aae294a6a292f16
2020-10-31 13:01:18
72
43
4586d1ba3586ca6df8b5d625289d7bbe0adbbf1c14a2844662fe458706b32c1c
2020-10-27 16:30:07
68
3
1af32589fa212ac48921f9bac1e36a569ec9614a0921bda681baa44df9e53563
2020-10-15 08:40:30
71
4
edc974efd6f6c4e46e26b38f501d8bd2177ca38b8035218d414003246b39fa4d
2020-10-13 19:17:06
68
6
62dc115ab49e9153f87946b2c2f02bcb59e6bf154fb825165e5aa7fbefe585cb
2020-10-13 19:10:40
69
8
b8341be43d339af7bf5a91429e80950fd62e915bc43399e524eac68b54ef82a5
2020-10-10 17:35:33
69
4

Rule Matches per Month (last 24 months)