SUSP_HKTL_Encoded_Hacktool_Strings_Oct21_1

Rule Info

Name
SUSP_HKTL_Encoded_Hacktool_Strings_Oct21_1
Description
Detects encoded strings often found in exploit codes and hack tools
Date
2021-10-13
Score
60
Tags
['SUSP', 'HKTL']
Minimum Yara
1.7
Author
Florian Roth
Av Ratio
27.77
Rule Hash
b9fa07bb326b18ec145f4e99113bf521
Reference
Internal Research
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
55
Suspicious (< 10 engines)
19
Clean (0 engines)
7

Rule Matches

Hash
Total
Timestamp
Positives
VT
45a9c0ce5c0acd4d2ead9be92f665a640c5a00dd1d3cf836f5d932a3f2683c9a
61
2022-08-16 22:14:12
16
84490a64f9fa38fab06f2ab7175e8372762d0098e9417f36ccd0ccbead51fbdb
60
2022-08-15 17:25:02
25
c0ac16cd560a046368e1424792c96e3202ab691dfe025062175e612394048f62
59
2022-08-12 12:24:56
13
51bd92416cf97df5e023b807cfd02da20d71d3ccab3dff7a26512813acbbb740
60
2022-08-12 09:45:19
41
84067015f5041202506976eb71722fea9b047f41d6db7737bfaad4328fff03dd
59
2022-08-10 12:51:54
0
0af1d7f5375c8ee977aa7a31822df207fa95a260c7bc52f1f66c9050c6fe33ed
59
2022-07-22 12:46:57
36
4b7772913a500d72c342dd6f536361fec9e8a0cc4951b1d0b5f9999ec26cb800
59
2022-07-12 03:29:39
9
19f5e8b92ccc12c9d6ed6184e382e25c769abd172dfa0b177f30ff9d35c56044
58
2022-07-11 02:18:33
16
6bdfa243d60bd2aad4461a433d0bc485bcbd9ff49069bb564471857c7c7b21a7
59
2022-07-05 00:20:50
16
bbadb8b5d8a6a739c47f1aa16cd1603fbf146600b0e4198c950aa008b26b560b
56
2022-07-03 12:38:06
1
90ffd614d36c82d785541c5e4575146e50d4ac4ba06f5040d54c791a54d69f85
59
2022-07-03 05:36:01
16
28852af00cc3897d5d12fc23ac9c69f986408f9ce4b0d0641bee947d8055c7bf
59
2022-07-03 05:15:57
15
326de61092f4cc2fede2e82140a2d3b20c61ae45dfbd999ed7941f7696969ecd
57
2022-07-01 20:19:32
0
fecc1ad9f4043d00d01d331ec764ffe4bd385539be94ff9dbb1eb0a516e522ef
55
2022-06-30 19:36:50
1
3a0af4c07c1639162030ecdf7f373a960518267299726b0c56145ba82d7b3b7a
56
2022-06-29 17:22:35
1
89c920cf53eb21be85717d6e143a7a4de773be0f90d2de363ce308586500f479
58
2022-06-28 20:45:11
0
f807d89878e456dba98848b79b1765746b808766de13e4449ca17cc0b09d67d8
57
2022-06-27 22:41:37
16
39389c16d98773441c279f318ae569df1b1d38a2497b6abb5d0d3cfdb612096e
55
2022-06-27 20:30:43
17
84cc7d785695ba4a868fa342845b05482f0627d46f506655c754fbf58148cd17
56
2022-06-26 13:08:56
13
3e8f7495e842dd1075a6d59bbe2dbb704386cc1fd1708d67751bd793822bf509
55
2022-06-23 20:26:18
0
e633084789582f606017f02da365c31369bfcc53deb639fc011cecc3652db701
57
2022-06-17 08:45:37
37
65b844dbf7bada25ca4230310394fb9242a7adde50a5dba23c99c788877b6a60
57
2022-06-09 04:08:42
10
31368f805417eb7c7c905d0ed729eb1bb0fea33f6e358f7a11988a0d2366e942
59
2022-06-08 13:17:27
37
052d523e4f30d9dd6efb6aaec69f47bee0931d86830d51ee06c2aadc0f8b3f40
58
2022-06-02 21:04:03
0
179904928064f65fdf3248379cfbdb9311353c929b52e1f10816a809651853d8
58
2022-05-21 18:45:32
15
c0dce390c12a6d5a56a0f047dee9039158ac405a07cc80cd557bb972941c854b
68
2022-05-17 06:24:46
6
629fbcb09530b7d7254332929915631df3d3849a7ef0f205391c26f92dc299a4
59
2022-05-16 17:36:27
39
1f05952075b975dca313cb21ebe5dec82c59b61f17f12c282627a58f84788185
58
2022-05-13 10:14:00
15
a20954509ff1303b1787256c97b96bbd3414e7614ef61f5b0e4017607bc72f03
58
2022-05-13 00:40:26
3
008f36666541b67bb81747daca544d130f0d4d29f344ee3b5599268e113d9740
68
2022-04-27 20:36:28
18
651a9b0c78d081ca730b73b15de74cbbcd52c9517b9366bfc2d54daf57c06bd0
57
2022-04-25 11:35:00
7
3520897e496c08940b813123d2a894c504f034928c0335c75b2839a04265291f
59
2022-04-13 14:58:27
3
43dfcc25c013b00e8898d5505eb3270fe29231f73f6127bf52d39397d0ddee84
44
2022-04-13 10:59:18
2
41cc99411556c30d1b8e37858d5cdd8b43dc5a3703e9914c4e3a661bcd9bdb49
57
2022-04-11 21:05:26
38
b4cc765d11167b1204b2ba8150f95824bc31ed83e856c3fb62c22a7f700cfa93
54
2022-04-04 10:08:08
24
6fb9774a2fdf89b25537a3641edd64dd8f74d61f351d22b141c2274e900f4e62
57
2022-04-03 10:33:52
31
091bc492610deeabc511b432379032afda8fd23aa7c63df888c40018d84bbc2a
58
2022-03-31 17:09:50
24
f2b1e1b3332397b09bc81cc4fbac146c3fe837ab574787d2e13bcad2c98a8413
56
2022-03-29 13:49:42
2
c95c3a628886df9026c1af3ad979f5715dbe50d3c2a333ae0ccdafdba1706bb2
60
2022-03-28 21:51:16
31
5df7abad2ac998ca3052a4ecad2f8e7082cb6372cd65623eb7afb4cdf9a226f1
56
2022-03-17 09:30:37
21
064c77760c16f2594b2de04a3e4d2ade2c13c6a6ad796bf1ae6236bfede867e1
54
2022-03-15 23:15:06
5
7cd242d9d6c5c18f14db69986dcb140393dfa2aa9931d41dbc154140cd3cba7d
55
2022-03-12 18:27:55
31
e031222d9c557c7598e08c939cb43950b900b9a683c3018b5975c000f8f68210
57
2022-03-07 13:20:42
10
70f925b3360fe2dcd9ac21d6f9870b861b5c56661439e99ce41002e7377d0e6b
55
2022-03-05 12:29:03
15
22a274376d33cc41556c59e76b529e4399c292957d2c2f872752e21cb385e059
60
2022-02-28 01:10:51
9
88f29d6937072e5e7e4eede5db2c3c208c2819945a0e60c053ebc3eac4109fa0
70
2022-02-25 07:37:09
13
726adf5e078939a319afea477d0770e4c577fe77901fbd37aa3bdcc00709aa8f
69
2022-02-21 14:30:48
25
e6d3a4126c985d7818b6abba77defabc86be4cd30dbb91e8912b0cae883c5b4e
53
2022-02-07 23:57:17
39
53fe7d23d833ac0328e43164f79168f14d59a18fe5abc0d10e142533dba022bb
55
2022-02-06 17:37:22
7
c337f2acdfd0f1546058c95c30426eae342643c80046d627fb94ca4c173235cf
57
2022-02-04 21:27:03
36
95606bbcccee23e85f6634c14f8830afa5f10ef35768c382fbdea30967a5f0a4
57
2022-02-04 21:25:51
22
c61d01c3fef8e6d9b75fe4ac1b6486d0e950e67a34ad1675aa74b14d082215b3
56
2022-02-04 21:25:43
32
56ef38d4d83cd8ebb2f288cec748732cd9fb6c7cbe6d9e9df2677d8ea88e0ed8
56
2022-02-04 21:24:32
33
c01900743dc5afcfbbf875f119683b3e064c7176fa4d9d80ac4c64244c50fa41
56
2022-02-04 16:14:44
20
558654f76d4a04619a797e7397e15995c7a7c8041a2f71791906b80ce966f2e5
56
2022-02-03 15:06:17
0
6df38813c65b6725434642f4623a543840065a2b6eff13def6394a169daf2463
58
2022-01-31 14:11:06
15
60db6cee7b64b0433ad234989fb0fb9683834ed59115c72f30331a74537878d1
56
2022-01-25 10:24:06
5
85a3c2a9aab8266e2310fa3e81f81ce92ff70a0af695d0229645291fddc50d12
58
2022-01-19 10:34:00
13
f6d4023be2d3598b7ccae8008c2218262722104727ec7a74f48a9ca99513a4b1
52
2022-01-19 01:54:37
31
e047e859e5cf7eeaf34d7539a1725ee6b3663988aa866ba333ba63f3e2a90ae8
67
2022-01-10 23:25:32
2
3cb4fa1c07af71ae7897309e8c66fd60218070c5061906afbdb1aca583d07f3a
57
2022-01-10 19:58:49
0
e62420ef46d5c4328961fa4223f0a0e068a7a6cc27bb92b9d30eb03ca9055048
58
2022-01-07 06:05:10
19
3214b8a24eabed4135481b1966c49f59c032b8bc37eef8c162ff790a58e997ec
50
2022-01-03 16:56:20
25
ce15d2555bc86fb29432e111599019a43ac0f3908e55072e76f1ff970d271d63
58
2022-01-03 16:27:16
23
336492ee8b20f2bb5b93035ada1343c2e08ffcbbaffdf91baf95136d02cf25a7
57
2022-01-03 13:13:34
28
4781c8dd8adca6b98a197ef08e098e3a151d8c1c63768f7e9861cd55ed12e857
62
2021-12-29 14:18:25
10
3caa83ad34660f6a65663d7315bb45ed66db07253a15a8cbdece82afadbb1d63
58
2021-12-22 09:28:35
10
b22c712b23e04ff61ef6ddd277c63b9d0beada06a74b14c00d4f6ca062f3eda5
57
2021-12-16 14:51:50
28
87bb5de4ecfea7272eaf57f16f34b86b9e6cec31f5e30d4bb47d45f339a743e4
66
2021-12-11 10:20:53
15
b3bfd37737e0cf55681136a057fa17b5283ca8dc60c2a6db4426033a5d9c7094
55
2021-12-11 09:46:23
10
d24f41b1dc9adcf05e72f3f48db137c21b3fa0878a6627fb88bd1351d958601d
56
2021-12-09 19:45:46
26
21a2f8792d1291ffc5a45bfaaa59bf21b33450ed94b93a7cd9d5f6ed71b0d22a
55
2021-12-08 19:51:39
4
f24330ea1123043497b94072452e5d7bdda66aa80b09367fe985bcfda77851bd
58
2021-12-07 09:17:42
13
f694bdf4b90c6e5d2e55fec073bd848a7bbdf70868feabb02a4e8e1f984a9f6d
58
2021-12-07 08:40:55
13
2648bb79ad71066b5f97379bbbb6fe71efe6e937d3b636db3b8efdf96521b532
58
2021-12-07 08:21:10
13
74277c384484623860acca35d26334d1084288ddec2acd4b18504aacf9bab52c
57
2021-12-07 08:15:43
14
2964f651222af493cdd307984c056a3399a87fa35306d608432467eb1645c1a0
57
2021-12-06 18:45:37
27
43d50466aba272a54f7554c4c639aebbe307cc336f389e78d977d3a0e025b16f
56
2021-12-05 07:08:53
9
5741d70d8ee99fcf5c84e13ba4c60ccaa793bc1ca94d8138485f6b75c01cd2d4
55
2021-12-05 07:08:52
7
838106a0fda0fa9cc6fd49f655a6cbebbb588dddab99763e8fe183c734e8110c
67
2021-11-30 22:16:18
18
dc32e79b9ac1db747cc0f755fcb1cd01824014cda69aeafcad63325981903af8
52
2021-11-29 06:18:11
6

Rule Matches per Month (last 24 months)