SUSP_HKTL_UltraFileScan_Jan21_1

Rule Info

Score
75
Reference
US CYBERCOM Report of 11.01.2021
Name
SUSP_HKTL_UltraFileScan_Jan21_1
Description
Detects benign tool used by Russian groups mentioned in US CYBERCOM report
Av Ratio
9.06
Author
Florian Roth
Tags
['T1086', 'FILE', 'EXE', 'HKTL', 'SUSP']
Rule Hash
6e1e70b8b426460686781f6c5280bf6c
Minimum Yara
1.7
Date
2021-01-08
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
27
Clean (0 engines)
0

Rule Matches

Positives
Hash
Total
Timestamp
VT
5
2f10ece60c4c879b7afb8b60b7079ee6337a3521e7a45ad1977725adb22d66ac
65
2022-01-15 04:03:56
3
1f42c2ea9a4742323ce9e2f1cef717667c4e1d8b0e2b472cc5f1600823bdeb60
65
2022-01-14 21:12:54
12
2f66d353d328888e8ab172ef28772c77584ff2a0151b6291270dad7c47dfe9a9
68
2022-01-10 02:05:12
4
f419ba40a1cc043f9e65bbb39cd0368ac7d2749d580c1a4936d23d981db96186
67
2022-01-08 05:40:38
7
bfa893bf7b8091c3676acb5c3ec8485f65382b996a4f760075d7f711ca9f019c
68
2022-01-01 05:19:48
6
b962954e05976e31af531c991592c2349d220be16a04c9d571a229db705dec47
67
2021-12-31 07:52:03
3
9e7ad97b156299906c935f638e60460026ebdae91bdb5282390a47e136abb24f
67
2021-12-30 23:18:55
8
f6db9905eff28bfd7c48a35a8a949f6eb293a0aae6308c3ca2431f05371097e4
68
2021-12-24 06:46:14
9
5a49aad440a6bae215a7f438b881d0ae61683fdd03622f3b12b8483b53b6a40f
67
2021-12-22 21:46:36
6
0e0b3152a0d2a803d8831360158d9bef3a3008a48864c9d547e98c17ee3b1191
67
2021-12-14 06:10:23
5
446f0b3f4fd28a68ba5dc1635adba8c4699002593b997aa3403157e13c0a59d0
67
2021-12-14 04:34:17
7
66a4f3b8f493fa751c8b26f741415c2174f8930d08f20442b6bad767cdeb65d6
61
2021-12-13 06:32:41
5
91bb502bf2ec9b1fb83b4cd92236b61524ffb0ba8fbf49195340bc7db659457e
65
2021-12-12 03:05:10
5
19a9a39a7f325be207e89baf2bf66285b735982201c94461c444b44034b393ea
65
2021-12-12 03:00:54
5
7f757df99d0f05b8bcdf8dbd09a6655463b7473fecf903f85126ba3ea29dc127
65
2021-12-08 18:33:57
6
e4275d19597fffd8df8d13c89fe0ec474338a11e60fa9400cbd1a7546bbedc40
65
2021-12-06 12:09:34
2
484988c3b0488ce1b8ba0408cac27359bf6338449b5555226ee2dff837025217
65
2021-12-02 15:45:23
8
34e7a22093e6d652ec7aef7479589c4f309507a4400e64112824b91a945fd67d
66
2021-11-30 19:44:06
6
8e26cefa252fc1fbecad20ab516eb419d86d674c997c02641969537aeffc83a6
65
2021-11-30 15:14:15
7
f1589906a7b0a52deb44a389a1ae860d442d45f1e29b5b00921f4234c84ad33a
66
2021-11-28 08:21:08
5
6395314dbdcb6246943c0fce4dac38524230e1733bdd7a679e78e98d99959b83
64
2021-11-26 17:08:30
4
07d9806ebd2b536464501dcdd091f8164f4a338a24a6ca1ddde20fa374606946
65
2021-11-25 12:14:20
6
86e807155d6fb5d39118e36d4fb9737fa3144b56df16e32dce42cadf1483f9ea
64
2021-11-25 02:16:44
5
1c2a9af8d68660e47f9ae0cdbe21d7bac1be161d2a98bd9ae82169450a653b12
61
2021-11-25 01:59:39
6
a0eb2f727af27746541c38611f4aab7ead3bdc9b7380402f147473a9b482bfba
61
2021-11-24 22:39:55
6
ef99843170e9a3e0ffe9fd4185fd6966fd87fb4c7a2af90344dfa115d37ef3a0
66
2021-11-24 22:07:03
8
fa8a549f856f09a2ddba206d406a36f571e53471c535a78c737059fda815625a
56
2021-11-24 19:16:10
6
f20e86c4143c264cec872c19d9db4d9df8d64d131b39d67b96b08af64d91a78b
67
2021-11-24 18:14:25

Rule Matches per Month (last 24 months)