SUSP_LNX_Back_Connect_Shell_Indicator_Jun21_1

Rule Info

Modified
2021-06-09
Tags
['LINUX', 'SUSP', 'FILE']
Name
SUSP_LNX_Back_Connect_Shell_Indicator_Jun21_1
Minimum Yara
1.7
Rule Hash
d7fa33c871224c0599be20207cb9f59a
Av Ratio
28.25
Score
70
Author
Florian Roth
Date
2021-06-05
Description
Detects back connect shell code as used in Linux hack tools or payloads
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
23
Suspicious (< 10 engines)
2
Clean (0 engines)
15

Rule Matches

Hash
Timestamp
Total
Positives
VT
f418b4a89d393bfc1fbd4ddd8021718b17dd1a29f7b7906c0773560e82fb11ad
2021-06-14 17:47:23
58
22
3f23864a7fce1ccf4c7c9105d312540887409ea7dda7e2bdc137475f26c19bb3
2021-06-14 17:46:56
60
27
6f187dc517aa47eb831ed302c7a4c633645fb397e95e9ba5b9603747d015bccf
2021-06-14 17:45:10
61
36
6c8ca8e50a289841d86b1bc3e67ebe0e668c2f9a9b3571fd6d3252c569f216f1
2021-06-14 17:43:58
61
34
b63a6e6981ac9e96abe9deb16d399a6f1d026fe755551ee908e79d699c063247
2021-06-14 17:43:58
62
35
fef8f7d62d7e9ebd78750ac0b628af416f0f5979f1d7ffcbf69a539dec418022
2021-06-14 17:42:56
59
23
a05422f5093ce07066354f8fa7ccfdd242380f01becf42383d72927ca3c32f54
2021-06-14 17:42:56
61
32
71cfee3417f7f7202a3b237fae3910f01177b79fb641ea12545bb573bb8d6afb
2021-06-14 17:42:17
61
25
80bd3d5e590a81ec59e741da471ab26004a1e01a968eaa4cb1dced7589fb3fe2
2021-06-14 17:39:46
61
33
eb59412d7cbefea8b9cb59a7bf06bb970f02e599df3b7d936193f37b29dcdf25
2021-06-14 17:37:40
56
30
d320bcf24e0e5656ef1393f66a94ab7320b5e45ce81dd719f1bdb8e48dac5d9b
2021-06-14 17:37:40
61
28
6f5581d041aa2db8de2d697c44a9d9ae53a9a6a6586f9dfa0fe1eed33b43bd76
2021-06-14 17:35:33
59
31
6021e85fa05bebfd1f274fcf2d72b2e9d3ae4770ea9b4c76a58f45b24f117a1a
2021-06-14 17:34:28
61
26
542c1cc154f2284d89f15584f8b969819677a21c394070dac6dfcd5b635605cf
2021-06-14 17:33:24
61
35
095cd6d244d2099df47fc56d99229d47f0770ae806ae1594b3aa52095b7a9666
2021-06-11 11:41:24
62
36
002b5aea92072e84933c3f7376df8cd8c09d50dc0c3277488e1870baf3d15a07
2021-06-11 11:38:49
61
30
7fde30c83ad745088213a2407c7301ae1d307774aacb8cb566d3785d276267ac
2021-06-11 09:41:14
60
36
3cfeb869c6ac00859dff9f293778bcef788b32ec7ef436f23f92508f86ac335f
2021-06-10 21:49:09
61
27
1583460b76ffaa0a1ab304464c3bcc1c346e2f4d9156fcb3713149bf11a10ec3
2021-06-10 21:12:47
61
36
0e1984d7ec6a4e73ee5faf9c77c0a0025c190c61dc7c7178761aa38741cab36e
2021-06-10 21:07:30
61
33
0def0b0df88a0835213f2e348ff59e960d70b76a5b5aef33b1a1a4154c707be4
2021-06-10 21:06:26
60
34
e7fcdd327b4588c7665c1cfbfe35acac6e44c8196291ebbfd3e55e6c8640efc2
2021-06-07 13:07:05
58
14
8956389a7a50dcf4b7ab221c1b91172e7f7fb298dbf43a8251abfb76334e7a4e
2021-06-05 11:23:55
61
2
8f7ef593382a93ea63a4643c3f501126bcfd5975567c4401e3bd1ee19e221740
2021-06-05 11:21:25
59
16
7fe4d08596fc13f16ed9bc29345a09a153e7e006bad88289836092bfc0e1ff1d
2021-06-05 11:16:37
61
1
17d1161cb5eb6148d98cbe61817e4ba27261949201ab21034161875251f2fa96
2021-06-05 10:57:47
57
0
12fea1c7b72be7adc3c17e5a1aec6b4faf8d29ab00b1317e6396387663efb25a
2021-06-05 10:56:42
59
0
1dfa1763a35d18b377ad1d505131a24822d95e1988a0c508bcaf16fe454596c3
2021-06-05 10:56:41
59
0
1cbf43b80d50d61b78f03d453581832404fbf25e712781f53835c31633ca783e
2021-06-05 10:56:40
58
0
0d4b4abcc03b71748b9177f4f94dfc0104eaf9ecfe90e2847495318c8698b315
2021-06-05 10:54:31
59
0
0f5455cd4128a5288b8aa301d40aa93d1a5f6aed14d3fdecd9fa811bbb52e283
2021-06-05 10:54:28
59
0
05fbd81a1c2754c53453e2c4dc2af0c3a21be40a24e02649706538d5140841ed
2021-06-05 10:54:28
58
0
0b24354e77ee4c32f12fa991ee91dcb66479304c6a5d9b4a6628e010e4494f00
2021-06-05 10:54:27
59
0
0b6083c90c7e0c6bb9876ee38c7993e737cb37dee83e77f455a1988e0f9e117b
2021-06-05 10:53:29
59
0
059543f9271c2537177ea2b06dc8773ffd4899caf11591cb0a6db4fb39cd5239
2021-06-05 10:53:29
59
0
0404daa510977eb930d2c57ebce45930786a7f734914c1863ea448618284dfa3
2021-06-05 10:53:27
58
0
031f22e9869bcbc750e0aa420c183712de06952a16bbc6083e2a07554e672547
2021-06-05 10:53:23
58
0
092b0dae82bb99cd71bd50eaee02cf4c3e1c51be43efb5e43db221d5dc068a50
2021-06-05 10:53:21
58
0
022d22576059c21c78c39297384985160ddb3e02b5244fe64aa40ebd4b559f2c
2021-06-05 10:52:18
58
0
00194eeee3333bcdedef60e7f1c2a4d6057fb5b7b25bcc979e9e3a9ddbb7a30c
2021-06-05 10:52:15
59
0

Rule Matches per Month (last 24 months)