SUSP_MAL_PY_Python_Pattern_Aug22_1

Rule Info

Minimum Yara
1.7
Tags
['SUSP', 'SCRIPT', 'MAL']
Name
SUSP_MAL_PY_Python_Pattern_Aug22_1
Description
Detects code sequences often found in malicious Python packages
Rule Hash
1550f4945d68b9ab9c9330c1b8e1b2ab
Score
70
Required Modules
[]
Author
Florian Roth
Date
2022-08-19
Av Ratio
5.58

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
5
Suspicious (< 10 engines)
7
Clean (0 engines)
39

Rule Matches

Timestamp
Positives
Total
Hash
VT
2022-09-29 03:37:34
0
60
3b0dcfc45bc3f4f44924c9e556852cf335577aa163a7d0b9aaf9ca9567068abc
2022-09-28 19:20:31
0
55
caad3f596a54d0252d9dbcec81add9345b39130cf58d55e02201090d34f36552
2022-09-28 17:56:02
0
60
59fc8967a457c8dadd403d1fd53feed8ac233887955da88b78b85642c7b6d887
2022-09-27 12:40:01
0
60
c439afe172e91b1565755d1cdd829ac74036dfc9abdbe80331fee3a047882d85
2022-09-26 01:59:57
0
60
6334a9c63164bdd2effcd1c9a8e4d9207a464cb2e7a2c2b7abe7e042ca0196f1
2022-09-25 13:40:09
0
60
37a8a9c3e64f947d7b59240efb4be06a6fc35f00fca422fd876548561fa36071
2022-09-25 12:01:30
3
60
c9d8f09944ad168ec9d7e00f43647b4f0b54d00ed33fa9e87c90b63e11caa74d
2022-09-24 17:59:22
0
60
23d44d0d5af095f26cb8bb4c9c34db635828ef7059b6c42e84dac7801e3e0051
2022-09-23 10:23:27
0
60
cba058c6f649c7cbe5b6d66ab17b85bdfe6eb4da0d7c91f2498f6f418b669379
2022-09-23 06:06:20
0
60
ff0522296e8f0c60a127305057a15325a81d5713e44cefebe86f0f6ac21ddc12
2022-09-22 14:02:17
1
60
e5ec0064e7093daf69536662a89c38d07ceaa09b82d62378b65b31300c751a97
2022-09-21 18:23:14
0
58
6fa57a1fcea5a4fd4fd5b8373ef31e0eb59fd1a9f49aaef997cb9c66bf1cc03d
2022-09-20 04:10:52
0
59
0cf0b5dd7a7df9e5824d7f0fe0470cf2bd33129f40b6b1fa9462fbdb67947529
2022-09-18 11:11:25
0
59
3f281c2064de931a351db14310847550a4fc29f6a431758c501bae5bb7b535ee
2022-09-17 06:07:56
0
59
2aa31f8869636d9d3578d59d45b36785f7fa8d39e4c75c21d5905fb796721565
2022-09-16 01:41:46
0
59
0648b0d68a770ddc95e123fce058b7d3fd30b84cf76f7f18e66da73542628bca
2022-09-15 02:10:35
0
57
fb8ffe14a1760d8ae71193b4563605ca5be06e0c7b18cbc8c6dd464196417803
2022-09-14 22:07:33
0
59
4ea05a42d84584f59d3b1e939ed6c4f48a0b81dfcb3ec8f49a21a5a068d32a5d
2022-09-14 21:12:42
0
59
777fe160a735064fe03aab6cb31afc20f9840a0828d880f5f1829244c06a77d7
2022-09-14 18:15:51
16
58
4041229baf2b48cb9d5f0890e8312d814f8b12d81b42b26d9015280e2788bcb0
2022-09-14 16:15:56
0
59
be99365f51ea18e974c83e5b36fd808c759cf58efac602bca191f75ae75f42bb
2022-09-14 11:15:44
0
59
1f75e2dcbd4b514d2965cbfbe737b1244fba1bcf524ef221a18e8348f5322c71
2022-09-14 11:14:20
0
59
41fafe094a7d9473ab77c9fe37e62195aeacc4e12b55f8b9e3666725462bbf17
2022-09-14 08:43:44
33
60
bae87311c2b03195a0372e220c59facf1e0ae01e9ded395c59b71e0cada42f95
2022-09-14 00:13:29
0
59
2125c5e24fa5e4746059835efc76e1aa5bf21d9815af5f603deeb72c7e96a6d1
2022-09-13 17:10:14
0
59
29b86ed34c073bcec723799f4c62d0425c00ab813b8859c521a6833266dbba25
2022-09-11 03:59:05
0
50
108a7ea095559b15652dd4de2e704617aaf0e198f1964e9dcdfa3c4f89fe405c
2022-09-10 22:17:54
0
58
7d4856d0be45a38eb4f60b3a3e668b813fc8bfe9f359d7b52be5f527a3dd1495
2022-09-10 19:16:13
0
59
ba7733559f8942e894ed5968b6b1a973782b1f4beb1bf51c945d6b1ec339e34c
2022-09-07 03:18:18
0
59
f808ae3c91a084bb1c1d81836e7a732fdef9b307281e8b6cc2b3452b5305bde8
2022-09-06 17:06:50
0
57
745e9184ab179027a69b9521ab42a2cb3021e53cf6c9922c4fe3ec7336d9c5c0
2022-09-06 14:03:11
0
59
91fc0f341b3511f0bd9c234402271ddf8101ee58ec98b4751bd0f0ce1c1010ae
2022-09-05 21:10:12
0
59
3a279c6eaa4f4e817dc29db85d99f5e217d40a554c18ac5727f6a14416f895ee
2022-09-03 22:45:14
0
59
206bbdf866c4500aa87327e81a0be461aca017e9ddbe60f7f794c993e53a3262
2022-09-03 19:26:12
0
59
9a5f768980b45299a0099d61257b1148440c35e700de6faf11a81a3f8d2eeaf5
2022-09-02 14:17:08
2
60
c73665ec9d5ee34ba79251ddf0b7d5b82994afa6cbd77999b242e245cf84a73b
2022-08-30 19:20:48
0
58
2469cd2b0db06dea354f3fe458dd279f14a2dee73fb61da4434ddb39d4789c11
2022-08-24 18:46:25
1
59
b66c272d6761d84e9d08f676ea64669949cacf47a281c148b8b59644e370f8b1
2022-08-24 09:42:16
34
60
aa66afee8a01c75581323dba4be51821e6801522b857383f347c32e6d230ee84
2022-08-23 23:07:22
0
59
0e61832f463ad089ff94d99262c0375cfa10808bdf4af0021b20d6b007464046
2022-08-22 15:10:55
0
54
977fe3702efc0d5a44a8979fc95f711e37d8477b5246c0c989493b73cf5dbbbf
2022-08-22 14:18:00
1
59
5f53044db10722aa9c61979efb618e49b356dd81d5deacab784430d555466edc
2022-08-22 04:23:01
28
60
5409a16b9bf1985c79c71c703fc9c2e2ea00fed36d2834f0ea97d8d6ec39f7eb
2022-08-22 03:43:58
0
59
1d68c28b24a2efbeee24b777685aeeb049b7080d8130984fbce629ddee60886d
2022-08-21 18:41:20
0
59
8f623c966e0b0b21945bdb9779ca9d635fc1a87a7cfe031323088e05970b09f5
2022-08-21 03:27:55
0
59
e5edaae2d1aede53e34ec5b186a66116e04f09ae77216ca109914fb2c64685b5
2022-08-20 17:19:05
0
59
d4d250618c9f3d591e78c24990f04318897a45ddf87a8404ed2a4fa71b4b6ff1
2022-08-20 16:39:20
0
62
f9ccaf46cc39b6ff4af51fb6ab87a99e8336b8dc0c361be41d13cdfce849efcf
2022-08-20 04:11:10
35
60
a62771e91cae26bed01d55364b63735aac78f856c8a9c12be51349a854eb3754
2022-08-19 16:39:11
7
59
508fdc0b628230796e7a62c22543ebb6d44e3cb6676e6c55aeb446ec53ba5468
2022-08-19 16:37:58
9
60
e50c8b14ef3bb0a720f1b3fb27ec7e5f04d65f07c87f268206c756ec4f1a5000

Rule Matches per Month (last 24 months)