SUSP_LNX_Crontab_Wget_Oct21_1

Rule Info

Av Ratio
9.88
Score
60
Name
SUSP_LNX_Crontab_Wget_Oct21_1
Minimum Yara
1.7
Required Modules
[]
Description
Detects suspicious wget command in crontabs
Date
2021-10-02
Tags
['SCRIPT', 'SUSP', 'T1105', 'LINUX']
Rule Hash
45173ba06f82b9a6d82aab6d4b73dcf9
Author
Florian Roth

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
7
Suspicious (< 10 engines)
11
Clean (0 engines)
12

Rule Matches

Positives
Hash
Total
Timestamp
VT
5
eb1db0d3f370e5c1698012df76b449e9e662eab10297f14008f1111c38193b21
57
2022-06-15 11:09:06
0
baa0eeff51c3d25cc473c8c09b373719f5c0d38b1d43eb8c2d27b8e9492fb38b
55
2022-06-11 19:44:09
0
a8a1672c179fb37a7ecb40564ed84b639e01c56c59f4f1e695a996935e876e11
56
2022-06-11 14:37:21
7
d0cf2c1b65c664643b92bbce9f88ada24cbdf1992d23b87497b402f426b34811
57
2022-06-11 01:30:17
0
682db452e498ddc88de931065c1286c164c1c10ab03b3554c51586ccc434a50d
56
2022-06-07 23:55:33
4
943f72c626f5ffb2775cdcbe9b646e8e576750bf24ba62793a2c8609b8526561
58
2022-05-26 09:11:58
2
7da803ddcc957c5c15350768aa33d08f734eb686824db30a64ca69678dce7a0b
57
2022-05-25 11:07:53
0
d1494794584a5f6aa4b4fc603c9e4df982f5904dc3bf3a28a14e1b47a6652cc0
57
2022-05-24 14:06:53
0
e1633a01dff67e62ea576a57660ce40faa021e4f5ab72243800ee92cae19d604
58
2022-04-23 20:56:48
0
e56da6ede5ba63969ed4407c0b90c2ae0f08dd68ecfc29ff3b1be170f435aed3
58
2022-04-12 19:12:03
0
352ddb44b0bdf60cd85f08a30839f387993e39b5533ff9f06d8a0eaaed667a99
58
2022-04-12 19:10:26
13
8b656fbc613826eafb5d392922aaf09cd780eb7d35ee7161b4b8b5a51a9ceb57
58
2022-04-03 20:10:22
0
6ddec0f9b80ddad110a94a2e39757679b6072f66c3a1838088e75df7037394de
58
2022-02-27 06:25:15
6
2a4cd08e61019f5813142d3fb691878b30f7eacd42b0941a30c2defaa8998d24
57
2022-02-26 11:20:25
0
e5db71a4cae258e7d14a6d3b1980708797a5295d86fe3c3892a11d33a464f77e
57
2022-01-24 06:26:28
1
85b2a5b9eced296c02149de03700a6f19dd8fa6c81e0e2dd73bb2e583eb63a42
52
2021-12-23 04:13:50
2
37ac51acc32af5e17da021cf9d10e3d93a755d490a49a84ea867fa7b5d479477
56
2021-12-07 08:13:27
15
5c26f10e53285161d92146f398f5d00ed52d73c2caa8cc1d731887bc9c409ec5
57
2021-12-06 14:08:02
0
b5715afa236c9ba9e4a3e279a01bc6e59d8256d3fae25b5cb1a14dc1c215c92d
56
2021-11-29 03:09:51
27
360d768957d92d36c4b9d715a606da4178fe17c74950862bd192b74bfbffc899
56
2021-11-24 01:46:26
18
404199777a6d1b0b1f02bd70299d374e5aec1649ae65a81320852b0698d47096
55
2021-11-23 11:47:56
0
c1c5c496bf94e1fdb8439081feb447d7060a026bb1512910d3dfd6f99aeef8ca
55
2021-11-17 17:40:51
0
ddd150fec762193ca11b791a2d8a3ebcfc88c81e820512df4dacfdeccb2d9b1c
56
2021-11-17 17:39:43
2
64cd4d10b0e2e9b47d203a5e6ad25ad8453302210d5b1493b7f6a7af76a1c1f8
55
2021-11-16 11:07:46
20
cfdee84680d67d4203ccd1f32faf3f13e6e7185072968d5823c1200444fdd53e
56
2021-11-10 15:17:05
17
1bca0088f84d9642002e8d403efb77f75596a9d9c50f171e587a66cc804fa971
58
2021-11-09 12:10:13
22
6ec8201ef8652f7a9833e216b5ece7ebbf70380ebd367e3385b1c0d4a43972fb
57
2021-11-09 11:31:02
3
e6fd350986dbf0c852a7d8a11b6aef178c651f2f29c27f79dccdf7f57c47a82d
58
2021-10-27 19:04:17
1
0be9dd7ea8ac7dad67dc7aa0833c46fb288b0da7972739f9656a74fb6125129d
57
2021-10-26 14:36:11
3
35697d8239c471d1f4d1d9a8fb1e141983a0dff4bee99aaa41b5dcd1b01a580a
58
2021-10-08 15:20:39

Rule Matches per Month (last 24 months)