SUSP_Combo_DOMDocument_Base64Data_May22

Rule Info

Description
Detects suspicious keyword combination in documents or VBA scripts that are often malicious
Reference
Internal Research
Tags
['SCRIPT', 'SUSP', 'T1132', 'ANOMALY']
Date
2022-05-10
Required Modules
[]
Rule Hash
d448a371eecea29be46a6b56cccc996d
Score
65
Av Ratio
5.78
Name
SUSP_Combo_DOMDocument_Base64Data_May22
Author
Nasreddine Bencherchali
Minimum Yara
1.7

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
6
Suspicious (< 10 engines)
51
Clean (0 engines)
21

Rule Matches

Total
Timestamp
Hash
Positives
VT
57
2022-05-27 10:06:57
694fe0c684b15ee85e76c83995674cde24949a88fe4818708940c8345f89d7b9
15
69
2022-05-26 20:16:33
780bb152049a5921fabbe0de066b53c36bf45d895b60b1651e35c69052e6703d
59
57
2022-05-26 18:35:02
7361c696feddaed4ef518c670a8cb38e015b2e43e87f910f33f21296f2c6bc46
4
58
2022-05-25 21:06:08
5c3fde60c178ed0306dd3e396032acdc9bc55c690e27a926923dd18238bbd64c
34
56
2022-05-23 00:27:34
3c555c348b3cf3c22a21946374709e0b012c723c6bc6cf2351d5ad9e29306caf
0
67
2022-05-21 01:03:19
5caf4de4e91b3dace71613c5fb8244f22569b6c0e33aad11c774468822d3ba81
41
57
2022-05-18 11:09:11
43f1286e8173ce233134c73401a629e32b6a87e896c97bed2a1ab88fb5b82a3b
3
68
2022-05-17 10:53:31
3d1a6f363cf5b5417f7b15a48484b721dcd9f8b86a4baa498a13371cdd8b5d1e
1
56
2022-05-17 08:59:23
79f810143b987d0c3df9a9a75a4a41aa6779aefd289ccfbc1e362e6cf3089573
2
59
2022-05-17 08:59:23
7fbde5d7c75c7808151c056eff25bd78e37bc0df312a9a675988462833b1d446
0
59
2022-05-17 08:59:23
2cce20e904a2d004272e886fb1e2dee9b87f3245f3dc56b0bb2695e34c30bc6a
2
58
2022-05-16 17:26:59
d521d52dc249396eed9b7c1cfb36fc0dd3c6b685bd7fc71961fb9cb0ec11865d
1
59
2022-05-16 17:26:59
e42e4f500f92a3063a33f8b94ce0b09e3be115150eed5c41f2dfb43093b13f64
1
59
2022-05-16 17:26:59
ab781e66cc418cebca6761097a0180191fcd8f46973576787b10689cac04c031
0
59
2022-05-16 17:11:10
95dd45ad3f5888bc12903c6bffe9f4bf439e04b429bb6ff01ab1a3774bf72df0
1
59
2022-05-16 17:11:10
eb9e4449b2a18c95e8ba98e769c9fb9bfd88d90702ffe40a4622a395b147e3fd
1
59
2022-05-16 17:11:10
31cdb54709caee8135815f8c5cef0cd7ed20c68fc69a25764248444e44eaab8d
0
58
2022-05-16 13:55:34
2d7b2b312c12b2856f16ef676582e200fad330d930a06bd5516b97d61d368835
26
59
2022-05-15 08:45:50
3f2c3ef7955163325bc15f104037af740aab181d4aabeae84a8cc9921ec043e7
1
59
2022-05-14 23:34:20
de83c7f3f9f4ebed1277909c34721c4a07d6636644adf3b3352311a6cb2e102c
0
57
2022-05-14 23:34:20
fec5581a1ceb69b1e4abdf1a6ca4e75431c23ed6613c04e58ee9bf5c680ed85b
1
57
2022-05-14 23:34:19
151bb2bb23a3ad5ed15bfdbcef41d8eea904338923049b0dad6558150373a517
1
56
2022-05-14 23:01:21
c72e829e5e6ba016dc9e11ace79a96533b92a411ccf4605256c207090a79f2f2
2
56
2022-05-14 23:01:21
2a34389b0e907f16a8e4ab4f7f9026718b93e3a38b7f8ff6c7c306d5144df621
1
59
2022-05-14 23:01:21
7a6b62302306b4112c58198204cc519b88c8e7e0cf2efefa7c41389f8d2ddd2e
0
59
2022-05-14 22:56:00
5bb1eb1c736fde61b71a534721a5bb1b296e8d1f99aa2ee0765929cf5836a660
0
57
2022-05-14 22:56:00
126eaf3c648d655fc0ee1e542f3401cfbf2af6ff54ebd86806d7aa4afdb7a6f2
1
56
2022-05-14 22:56:00
3f6ee42665b785059f658ef427396794ef968ff3114ec0f3b119eef297d0c369
1
59
2022-05-14 22:50:28
4daa27579e04149068d8162bcf26729297ca6933ad37d373c1232c4b32a3dd27
0
57
2022-05-14 22:50:28
31d0e3539726a2b91897a5d923deee1afd8aa99747e14e58a3f07ddb4a4f81b3
1
57
2022-05-14 22:50:27
91af05588bab83134807376562161d4c389ef3eb9e75073d0725e39e54f804e7
1
56
2022-05-14 21:25:27
e3841ef6b83b0bcfe96e78594fd71641e79051d5c35f79ed89c93b76223a059b
2
56
2022-05-14 21:25:27
ec402d3958a9e4d04975e31ddbe41471937d71fd9daeb394ab86638921a3e13b
2
59
2022-05-14 21:25:26
6cb1d453151c4a4d7f73e2b016d7948665bbb1bddf3655114162cfe15ee669ed
0
51
2022-05-14 21:16:00
807bbc12c59f9bcd3615139b5f12b332a0a11825ed23dad56d9dab18db9937c0
3
56
2022-05-14 21:16:00
01d859ba6986a5c1bf51b5215ede1994f916e436995e9ceefd094f900d80f677
1
59
2022-05-14 21:16:00
bc0887960230cfcb59855057e8c7e3da5e8f157ff98d9805b960f23f2cf5bbe1
0
57
2022-05-14 20:21:02
9624e67c007f1c2292ec70c954260d9e995b8b06c9654202d5d2ee782da06ad2
1
59
2022-05-14 17:02:24
6a835ae51f07f4a4576be52c4ee38d27484d6897a4b883ce0b8c90c17cc8d5bb
0
57
2022-05-14 17:02:24
6401d3bd46ae3d98e2bfc57b19bc9933b7589218615fe8cf517b24f1ea833f5d
1
59
2022-05-14 17:02:24
416c857fbbf4625a9fae8fab2a2bf43bf9f8897b2dfc3ca5304eceb4cf197080
1
59
2022-05-14 17:00:14
4e73430eb191ff7b09e6afd1eaf089be79356c6fd381a7e04032ca320da765c7
1
59
2022-05-14 17:00:14
5b643a4d7c22ca84c4470be430d6c383787a3ac33886e7062ab774297cbeceab
0
59
2022-05-14 17:00:14
61e5db4b2d56ebf7671d082b6b33d017e66c74e50847b933a37b13245be33d19
1
58
2022-05-14 16:49:26
0f5373a4c448719dbccae1afb866c61d9ec119403eaae7de7bffaed351ddf6a9
2
58
2022-05-14 16:41:58
f4ffa15f47b5feef4a271be54c24f71cb203f4159996c33457acf18b3e2ea3fe
0
59
2022-05-14 16:41:58
dbb7d236d900f9b50da8ba1831a8db345a7c5362f2acc5fd2eaeb31a134b0333
1
59
2022-05-14 16:41:58
731837c603c13c5417c3efeda1817e31301ae8f75e72e83e8c6b0f2d6584ec06
1
55
2022-05-14 04:22:48
a4a76ab16d51f990a749951368044dacca7bff3103448c582e2b6fe2cfcf3207
1
59
2022-05-14 04:22:44
c537e599690c1a4e261dbf41faf85a3ad6d6d9a24c9dd9474aa128f6857b2656
0
56
2022-05-14 04:21:32
214cebc1c4d79d62b13eeb6d2e2a0f040e8c6c627d0722f21db4314d54a81276
1
57
2022-05-13 13:51:44
c0c8f43205aff25e7d581de456a6e15f2e691b7a863a994b9a78608532dbb5e7
1
56
2022-05-13 13:51:44
777d199f2233ceca0684ae545ce09fe5b9e5f374a490e87c7f1a3b72c3ce415e
1
59
2022-05-13 13:51:44
fdb20b70630cb52d3df9d1d958873a31bc26a5833dcbaab0cf6762ecdd3ace1e
0
53
2022-05-13 13:50:35
c45aa7906c13cf9e3693e9c9f4331c06b8b3d8aeebe93c6d638bb3b49871536f
2
56
2022-05-13 13:49:17
e5aa180315c51a77112d8d4cd57aad84585d6b805bf0346f15b2b444ce608b54
2
55
2022-05-13 13:49:17
a020664cbd88c4dbd8071cf04719ba2cdafa68feeae276f9ad1adac393d64021
0
59
2022-05-13 13:12:11
3aad68fce415ef96f6eb21ee9c0c49f557e2d535608f8ea9e099c6abcb3a119f
0
56
2022-05-13 13:12:11
6d2e45f3201e3d01870e30b1213089d67b3985c35f8f8bc594102e28a45202bc
1
56
2022-05-13 13:12:10
1041213b7ed5e96b7f66a6d206be428b923d89b16a2eb6dfd3146b035a65db88
1
59
2022-05-13 11:18:46
564031f7249cbb7867f80233e18b71a44df7026134ec929d7d9f10b300a6361b
1
58
2022-05-13 11:18:46
d505ae30b5c4ead342244e50002569702dfca509979066d9ef5824bac158917b
0
59
2022-05-13 11:18:46
bb63da26c1ba3962c3a1d78c3eed3ca631a47533a86ce94ccc10d889659dd969
1
59
2022-05-13 11:16:36
ca2698a4f50ed10744b9ae70b832b5d8622ca5ac43cb30f9c8a19584ecb71cab
3
59
2022-05-13 11:15:25
777ba40344e678307e2b0ec9fa701f0643b317b9e59183be957db6546fff9077
2
57
2022-05-13 11:15:25
1606f709265a591a4b2ca78ed84798a349de61c23ad32b6a4ce68fda551c8cad
0
56
2022-05-13 07:20:04
43c77fccbf829501589a6e01abee8ecb576246015118f1f00216a64b55d77bd4
2
56
2022-05-13 06:59:22
3a29f8ce1b5ff4d35c89c5efd80b867099bfa4f914900c324bb3234b69544252
1
59
2022-05-13 03:35:26
bdd04276233f7c0e50dda66f8cf39fe6438e6d14ecde2f36e6b6c2644cd72c0f
0
56
2022-05-13 03:35:24
d90954739b76fba2a318236deb63d011b1108720cf6c9599480380e491691c3e
2
56
2022-05-13 03:35:24
e879a060ff84a5be045c5c6665a926733c0852aafaaf2c8bd9f9feeb188f76c6
2
59
2022-05-13 03:09:55
16ab8434f567950847d3d8e7c1c22620452685401dbd53584043ebb53aa864ce
2
56
2022-05-13 03:09:55
7c1460779e42296fe8a22873bbe09f6b4b41e99d42c3ee931d7631e6f0d257a6
1
56
2022-05-13 02:52:26
54c44425518f7269272a886270228e31a840e57fb0a76489f89f3f5b02da3dfc
0
58
2022-05-12 22:23:13
8f96cb3bf1cce83aba132c87da5486d790c518ea2f65e0e8832eabd8ecc74e27
5
57
2022-05-12 13:51:15
dafef765764e4ce52863f2f29b4ac8fd1b811839a29ce7f7bff7ac2852e90280
1
59
2022-05-12 13:51:01
8ae9b578fffc0d7e4f0c74e0e128dcb552f94a73c380704e92a08a8ffacf008a
1
68
2022-05-11 16:10:20
d3b9f75cfd77e35447d31ab1c63303c943c5962b340926b1b97c7511fc7bcc48
27

Rule Matches per Month (last 24 months)