SUSP_GZIP_Packed_Base64_Encoded_Executable

Rule Info

Date
2019-11-11
Av Ratio
3.82
Rule Hash
7b25a5b17bbc499682ddbd15985b6b5f
Score
50
Description
Detects
Name
SUSP_GZIP_Packed_Base64_Encoded_Executable
Required Modules
[]
Tags
['T1132', 'T1045', 'SUSP', 'T1136']
Author
Florian Roth
Minimum Yara
1.7

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
5
Suspicious (< 10 engines)
0
Clean (0 engines)
25

Rule Matches

Hash
Total
Timestamp
Positives
VT
e96f18f5d28e4017315e6a43ccf460004ee53b1acc305a21cd8c52d80ec7c81c
59
2020-10-19 22:16:23
13
9f8800a2ba98880e2c1ca21669e24d441b9b7b000e2230f8cecefd68dda6cc21
60
2020-10-19 19:18:00
0
160fba8e1ee13af2c610028304ec7e11636df5539bdbdbc1ca598491c20fa55a
59
2020-10-19 17:25:55
0
8cfe7a1dcc7845edbb63b76f5340592631291a7c7aa366817666c7f74df898b6
52
2020-10-19 17:00:43
0
3efdf0ea45c963faf23ff92cbb86c396568746432a404c8a77dab0c092975bad
60
2020-10-19 14:36:30
0
9a8ae9b02f8b9b47e94cef0befe4696d17918c166d7bc0094defd1b2e837e5e4
59
2020-10-19 09:28:02
0
17bca55fc04ae41e82a4407e938ab19daabee410b412da2dbe2fb9e3fe662695
59
2020-10-18 23:03:34
0
a67c840d9ea6e91f420f34d8fac629fe670029fa602349b95b8bd65d713ee5d5
59
2020-10-18 22:36:22
0
1a91e45afe7bd04339524989c66ca3f7b9025dc1bd1ff4f2e333f7015447d392
59
2020-10-18 01:27:32
0
b7b0f03a8b421d7868aa89dbb4ddc3f4dedb9031190fb66eca644c893004a253
59
2020-10-17 21:55:28
0
b7bbb854f0dcfdda253c855329ef2a6834ffc48b81761e472a551365ff46dae3
59
2020-10-17 19:13:13
0
190543aa06ebe3e138446863b7675f2bd20d2c3c11592d0214d6c6ac9b0d0f6f
60
2020-10-17 16:49:36
13
2e1ce518c05207a777a17f8e8094b2a752d01db6c6f27f32095e46e2c6bedcc8
60
2020-10-17 00:44:13
0
a66334b02c7cc34b9a1eaef6da1fae8be67e1e57c41928c72e677e15e5d74f7d
60
2020-10-17 00:21:35
0
4a23d70ffa80a8aa3f3ae8f343a1009d0a754442cb2e44ee2f211dbe17fbb8e2
59
2020-10-16 11:40:32
14
aede401da5a1506ffef733f0bb09316fdd95f2b3328f576329d6ab3c1cedd4dd
59
2020-10-14 02:34:24
0
a7466a0d6dfa1058a78bdf052e01d2f10452cc300b7631eb082cfd57ed170909
59
2020-10-13 20:56:48
0
1dfe6944bcfde44d29c8c5dcc715b12c4b363a1a313ac030de70f8b4c5381938
58
2020-10-13 20:36:09
0
569271d2b9a04262e4f06cbc3b71b410685e349022ca91f1243cf09601caecc3
47
2020-10-13 10:10:52
0
ff44db2e5ebc6938b37acaf909605b8da35e508a0348e5dad1a80ae5b1b8413d
59
2020-10-13 10:07:00
0
9cd9242b74792e71ef794c15d992e4a37c149f1ecf86c7933f5108721cb8584b
57
2020-10-13 10:06:05
0
7087c216c04d30a9d810c730fd865384697d5d624d3990adc0f58522813bcca1
59
2020-10-13 10:05:37
0
c88b6c96dfc51184a9be9e5d7bd609b9c7db0c0cb2f2b3a570e56d05b10658eb
59
2020-10-13 10:00:44
0
86f1f6fd9576d28a775682d82bc6f68dedf5dbcaef22111510b3a7eadf140280
56
2020-10-12 22:09:47
15
1bed705f41db3b902a6276c3949bbe4f103090c7bfadf38d76ab9befc54424ea
59
2020-10-12 14:06:47
0
17eaaa223cd777e383240fc9ccc5a04e9c4d28eba2d61c6c1c8403e4e25e0eec
59
2020-10-10 17:35:06
0
973e8ddf52b8afee9c44c614424be2ee64f412f22584bdc0bb0db3902c1bb43c
58
2020-10-10 17:32:11
0
fda5249ac334dd67886945eb00083f6c23a053d616b5bb0c3837226979cb2b8d
59
2020-10-10 12:47:21
12
11d829478fd70bdd1b2cc6c0fbcc2bff2170c7a872d65dd3441af1472dc0af95
59
2020-10-09 22:02:45
0
2a1cb4ef3ab7a7c6bdaf2de655cb024008cb2525b5b3539f4050b9628b78158a
57
2020-10-09 15:43:06
0

Rule Matches per Month (last 24 months)