SUSP_OBFUSC_PS1_Bypass_Jun20_1

Rule Info

Rule Hash
68181d520693ecf16753faaa003bec1f
Score
70
Tags
['SUSP', 'T1086', 'SCRIPT', 'OBFUS', 'T1027', 'T1136']
Reference
Internal Research
Name
SUSP_OBFUSC_PS1_Bypass_Jun20_1
Date
2020-06-27
Required Modules
[]
Author
Florian Roth
Description
Detects PowerShell scripts that show signs of obfuscation
Minimum Yara
1.7
Av Ratio
4.59

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
68
Clean (0 engines)
3

Rule Matches

Hash
Total
Timestamp
Positives
VT
821be501fb0bdcdccfaa50ac3548bfec7422cf116c259a157c7bd8e5e588f5f6
58
2020-07-30 19:44:54
2
6182b673e829dbd9e69e46783da394b0c7150027775ebae2b86666891a6dfdc6
59
2020-07-29 08:25:31
2
b504ebb22067eb1880bd190dadc278398dfcb23805fda016ccb56170f2d629f2
59
2020-07-28 22:42:39
2
7408cd8d51828fc5744a13b4c12c8c8c3125b953e93a98b7de89c0487131cf44
59
2020-07-28 22:40:39
2
8a7d2ed5a984407340d84cdf03e37e1d12a19a274ca0ac70d42fd602f9a83243
59
2020-07-28 21:41:27
2
01b512d1390a7f2edbe0fb898e142a7a0e49a61dffb34159a855ab95e4051239
59
2020-07-28 13:49:14
2
67de024ce62a5e7884cac62e5f15d7e543f1a3d643bf2fd230e1657a4cea632c
56
2020-07-28 10:25:38
2
ca5754611b8e47e2c51f26b7e6445b7f1ba717a54c11c1077f3e97e5edf0bb8f
59
2020-07-27 22:36:53
2
043d7512347a2386eff06ff396c85d191642b9dde068afc9a268730b8a4e1d73
59
2020-07-27 22:24:00
2
840cc6102dfb1ad0613e4af2c8c4d775bcfda3a0f37d9e9596ebf8bc7ea1155f
58
2020-07-27 21:45:58
2
9f7b6f7759945dbbf6385de526cecee867cbdd4cce0837ea9a22bf97e24295f2
59
2020-07-27 21:34:03
2
f51ca1325d8ae4c560ac2ea0c533684be4d4618844119a22d674c97dd10e10ee
59
2020-07-27 02:44:16
2
73689c1ccfd5ee1a618656035fa01e7f0c2b27eca2e7dfd8e1601454fa7a77b8
57
2020-07-25 01:58:11
2
09de040ccba79b0fbcb1964ab90c031b63f5a733bc61f674ff70d36fa83db766
59
2020-07-25 01:51:25
2
fc6d06effb063541650030436c9feeeae7cc29268e3292639fa7e56d356c0671
59
2020-07-24 00:24:37
2
4e5aca2268b6686c274ddab0c8b9cc3259350c1509515a26126afb4d56a0e9ce
59
2020-07-23 13:48:25
2
0f3283012605d1981e2aa492142113526b04199d990a418cd73c3a5a9cd3e4c7
59
2020-07-21 20:33:40
3
b92369a4f04bcdc0e8f4eec60bff8655174b2d99ea4f8dd49f95ac85dc2cc754
57
2020-07-21 14:06:08
2
cbd95bc5397caceb0a750598ecdbbc8491c9b578fbb76ddba3563c7e2ee958db
59
2020-07-21 13:49:54
2
a774ef81e2761e275436b942091e2edd7d91019be9aab0002b5d2a13215915c3
49
2020-07-21 13:20:25
2
7739913d14c36a8d679e2f5dbc6fce7a194517f6c5439091134cd9dc3a86ca2d
50
2020-07-20 04:47:54
1
6015bba293237bfb0c8057dcf2bdec728dc26dd541f5ecd662abbc3ce3c69470
58
2020-07-20 01:44:02
2
111f819ed5eaf0cbcaadc4d945daaf844b038f3b98c3f4465d07f62c49f7322b
59
2020-07-19 13:32:16
2
5f8e0fda21e9e95268cbd1ab15388b65f921caeafbde44dca1df59f40dadf2b0
59
2020-07-19 11:59:05
2
a715125eeede40820236936ac1ddb9e4975d33079f46e5b7c8fdfaf43d292208
59
2020-07-19 10:02:17
2
0d821116dde270823d72dcf9279ede728bdc4dda8e07d73c595aea5c2f124f07
59
2020-07-16 12:27:16
2
194003850bfdba1ab96ae073788c50985f69d878ef40cfed9c2dd47f68562904
59
2020-07-15 19:45:02
7
54c1d04ec3e825c4b1440468c59dc0bc6cf72e787af82731f5e7282451c2b4a0
59
2020-07-15 06:43:33
3
56795e3ba99ae03ff200efb62b6c07f1aa5ee0981cb9476ab406d4f544b6c7a0
39
2020-07-14 13:11:39
0
2e6ca28d494d652aec5a212c3d9fc8df980976b0b8d05408066686f7ae72ac68
60
2020-07-13 10:48:05
2
77a98bc5bee172fade7bf46e641d343aa7fa75ecdcf2c677c8cdd1d0498b88a3
59
2020-07-12 19:25:33
3
a270112dd06c4d7f62803cf2640e4a72c3f3d59da06356b99b598fc9e434cd76
59
2020-07-11 19:14:45
3
90a87d7c8451164cdec6a95828743f09483cb2dbe7af6094416b23f9d1e88075
59
2020-07-11 12:12:19
3
429030330d9e045c48cec3a81295ebd626c40c3e7487aa4bf4ac591bb15afa81
58
2020-07-10 09:43:16
2
42527fbe968298fade1d30551eee2ca84cd6fe588e360eaf723e54d036041f32
59
2020-07-09 05:21:22
2
a20723f6d5d428032ea58f8eff6e5945f4d9e8e4e8a119dd0ed8b50f9238248e
60
2020-07-08 19:10:55
6
9e35e04d2d9c6cd968fe66bcb3b09d0495eb69d9b76a569e0dd26e9162ee6f02
58
2020-07-08 09:21:44
2
09d604b4d7cc5f368c08b98d2765d807540745ec925911aa69051eae66c678b2
58
2020-07-08 09:10:22
3
2ea98e097b6568dc78b59c0e810d3957104f9f1e0048c8d8a6472d195a3b1345
60
2020-07-07 19:58:09
3
56c2bd969e496fd0fece22bf478a3b96c60e9ec0dc1e68a72640a98a0c0469e7
59
2020-07-07 19:05:39
3
60d24c7ae82b639f1f7488e085272b04172072b333af1d67a4fdbb30d9907374
56
2020-07-07 13:01:25
2
9e960530882ec5b5a31be5811bc3b98d60dcebf676c93af7fc0369dd29f9bbe9
58
2020-07-07 12:47:41
2
1ce431763cc6d213322333f5e38d979bafd396cb58c05d4472c9ef490ede56a4
58
2020-07-06 21:50:32
2
257426da34fd80e741ae2d4ec3e4721b62b90e82418f5a7a66c9bca45b287405
58
2020-07-06 21:16:01
2
fdff620e117dc134086db795cb3a141ae1fd043e72dc94993d6515ac7592ec5b
59
2020-07-05 00:18:50
0
252bda9c9dfe8eb40447fe7d287d47b74946b2fc904be1971fe953a678e0864c
59
2020-07-05 00:17:36
2
1d4625d22e303abe5c7e0fa33a271abc470d03340e6f23f1a806867ee8d8bacf
59
2020-07-05 00:16:17
2
3c1efc5837cc336e3bdd32eb0fd173495846b50a9845c4d59b1f428023d3181e
57
2020-07-05 00:15:37
0
74238fd85bd62ce156468ab68f642ea8ad0dce35ca37fa690838d6df37b34fbd
59
2020-07-05 00:06:58
2
f06c9996653251bd55319547a19979b00241d9f8d401cee42031699d045a462e
58
2020-07-05 00:00:52
2
db1cde0d74c13efded3af274f176614579a39135e2e051e191261c7cc533340b
59
2020-07-04 23:52:55
2
8d5711523cc43656f23dc8e17d82fc91cb3cf2f9503486bbec3e376999802232
59
2020-07-04 09:39:31
2
28efe80deb12aa8f238e497304d587ae16a0fddf3f368a7aea0b4bae9a23aa68
59
2020-07-04 07:37:05
3
00f8f019430943c88294cee80a88ef72c9b645e9b0e2b8aabd30491240655c0d
59
2020-07-04 01:28:54
3
98754d4a13f1d1836780bac2d099315dc024fafcfd3d3a55474f68b4ee359f65
59
2020-07-04 00:24:43
2
f0cf1f6fe6bf206a4ebe396df2a00995b64af1a97bf1bd5897c558308f64bf52
59
2020-07-03 14:58:09
2
9e7885743e15912ab7284edfe9ef1113d7fc65568a12e1b96ac010598afa9fde
58
2020-07-03 14:56:33
3
1d9b808ae25cba0aebfbe0464062771731c04c89d24aebe86f289f9e3d84a2b3
59
2020-07-03 02:29:13
2
22a86f0fefc088b43dbfe36249eac14c28261f99ff30fada6577359e8208a2c5
59
2020-07-02 09:42:36
2
227bdc107abe4814a36b30fe1cb64ddf401375d54eb3f4f0a63850fe5cafab21
59
2020-07-02 05:03:25
3
e954940a23037859c3a43c142327c6a0015c8cf5b5258e310e4c1d8d96275693
58
2020-07-01 13:32:12
2
436235ce80c2d365befc0d41e29860faf208e43fd852d95920c4442b2ec42126
57
2020-07-01 13:26:22
2
5ea41ebe49687b85cde075557f1a9b8b23cc1da19273b8e5c21f63f2af7b4cc0
58
2020-07-01 12:20:41
2
42ee9fbebeb49be3593a5f43bdfd6ee1e4173ccb96c1edab09af3e9333eb112a
59
2020-06-30 20:22:12
3
9e68ee7d48868fd7172c1e6f6285bc39c695bbf2ec5847a496b3284adfc7e59c
60
2020-06-30 18:40:54
6
d4a0d18bf8f2cceedff489d775f322883b2f5c0e6dedf2abcc955d5432692608
71
2020-06-30 01:17:45
37
ad7caf5a192eb020365b593862c4f0699462c86462609611b38bc93135f9a78d
59
2020-06-30 01:17:22
2
e451fe05cd426c94a217cda2fa3c4a3c6165cbebe18158b389bd88501ccb0045
59
2020-06-29 21:50:16
2
82441ea9aa15f7c54a4d564459ebd684483dceb4aae1396915cf6f9773233927
58
2020-06-29 17:50:33
3
c68a63734630e57f8ca7ce09554fa15657cc54a52aeacde7c5b0a72347fd51cb
59
2020-06-29 13:36:51
2
3d80c9c9b1948d80da3370bd599b8ada74efae702c9d65d050451a94e1b1bddc
59
2020-06-28 16:26:35
3
f4d27c4ceb75d3ab00915a92a7b1c6b9d03029fe836e85bd6ef1daf473ce11f4
59
2020-06-28 02:12:15
2

Rule Matches per Month (last 24 months)