SUSP_OBFUSC_Split_Backtick_Obfuscation_Jul22_1

Rule Info

Description
Detects charcteristics found in samples that obfuscate command lines using split up values
Score
70
Date
2022-07-08
Minimum Yara
1.7
Name
SUSP_OBFUSC_Split_Backtick_Obfuscation_Jul22_1
Required Modules
[]
Author
Florian Roth
Rule Hash
c6dc95dc758ea1795f163431b31b24cc
Tags
['T1027', 'SUSP', 'OBFUS']

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
14
Suspicious (< 10 engines)
50
Clean (0 engines)
5

Rule Matches

Hash
Timestamp
Positives
Total
VT
62099a166660602e38d105a803bb76102aeab81a8d71b171552b46aa22ba6da3
2023-02-09 01:02:54
3
59
5943c480547c04b5eab0a9a1ef45a2e1afb10292a0f6de271f0618162627ff2a
2023-02-06 20:37:00
4
60
bd73b6a9d51a099d626f7ce1685b760803fe5ddb4f26c129dc978c143dd811b0
2023-02-04 13:28:35
4
60
817fc552ffe372a573f9613e8f067b9a1fe10fc8175648ac0792f57f4682d122
2023-02-03 03:01:04
4
60
6a535aef5e32f7b0fcd418e42459f150a758fda64ac3d681a25b422966b1c593
2023-02-03 02:56:13
4
60
7b27dde38ff01e5d2ca68e6702636d679f4a16a44af9c51307d2be8254313b78
2023-01-25 19:05:47
5
60
f88bf820bc75d4cbbc1a06cf6fa6bf551079d02dc7e8a5af7f2fe89d9ceb339a
2023-01-24 18:46:02
4
60
66351d16d3bbf1f0c0d893a23a8ed53b135cf09360f3f57bc9b41f9ed5f8b7fd
2023-01-24 00:36:05
5
60
0b619c3267ab9efd9b0c9add00a1f8a8d4e48b0661c15862d84af34d89d8daec
2023-01-20 06:12:42
3
60
7dfbb8a4c540ea3cec087d669063ebfa875d441573b9b5b637dfca41f9ffa857
2023-01-19 07:47:02
3
60
9d253d712c8a1833058cdd19fa722db9b8876b65b705c18b970cd8920446ecde
2023-01-19 07:42:18
4
60
42994d6dcccd179df9be339777adbf0fce5578b95396033e8d4cbe64b3401bb9
2023-01-19 07:38:25
3
60
6f13b200667f4c86041e72b746cfdd49ac6365746598dfcf22833d8fffa40539
2023-01-19 07:32:12
3
60
986f335605c5912b89d07ebb5e2d01ba8784838d9bec9202902bec2aa74e326d
2023-01-19 07:31:07
3
60
ea32cb37bb35ddde9a0eaa9bf179824f62b7d1527c948c40c00dcf4aa3f2f998
2023-01-19 07:19:57
3
60
8e4baab4b28c069d8e2844c41573390d785831d9a777c763bf9574c12509f395
2023-01-15 18:59:38
4
59
5d54d74a8e704a36914269ae89cf605fd56f3ae028ceb0169bd4649f7decc0cf
2023-01-15 18:25:11
17
56
8bd9a089e5feffa907a2a4d67206c2d4e72d866c78e2504ba99cb2f5c43c15d5
2023-01-14 13:04:08
4
60
456a90f0070df3f830647c13f89ca0d2ec42374d527be15bf4ae9c0446327919
2023-01-11 23:01:51
2
60
6489e4d9b1df15de594ab20582daf7a0911e5157a26ed4d14f3fdae05b8f0330
2023-01-10 11:38:32
2
59
2e6e6cde723ff82485d8faba54e93fc382b77ce466d0e66af5d444a6d6fa65ad
2023-01-10 11:36:28
9
60
6985c4624c76abcb9f709c2ec300412fd3d5e2f17a137d6817efb944c3ceae6e
2023-01-10 11:36:11
13
60
e7f0538b811f5cb42ff1147f3c64d8560719de14f94cc3b927e0c3930c118a4a
2023-01-06 16:48:57
4
61
819a0c82a2c44729868b29f535d895ed99b0d918db29d663e61fb3f59001b13d
2023-01-02 16:46:17
6
61
18bd09bbaf8e623da61a8d38f0dfc434690ab8689fae8840d773eecffb701541
2022-12-27 02:31:28
2
61
8232ace58eca9ad32b338e9f3eaa7677d1f648b0686ff306ed1281b5a581e147
2022-12-24 08:17:15
5
61
51606c72b176d39354fce6c649053e1412f28838cc3c922bc814ff46d1f497bd
2022-12-19 17:08:31
28
61
24cb90d2d356bd42093632e79f278bdef7d5b09f6df49079c8170d874f343c6b
2022-12-17 19:08:07
5
61
5327d606e346a99700b2aac88cb4d0139f9511f9ed9b6664a74371be34711eb5
2022-12-14 16:22:04
2
61
2f83a87dc310fd1c73e7223653881ec5ee873821e909a6972c432cf27fcf829f
2022-12-12 12:39:22
9
61
ea2a0e6561a6fd8eabd9e733bdf086b76db2e9780c09f284c066af59bdb4f497
2022-12-07 20:08:15
0
62
6f31ef5ea65f55ae38be771219d7cb78176c26708aa4ee2097e9d58c15d1f9c6
2022-12-04 15:00:32
13
61
701015a7cdb626bc72806df5341de547fd2b5d92eda0600892951ffe40d1e55c
2022-11-30 17:17:48
4
61
77e1c16a73160894ee3575634a90c3d4ef9b479131da7d82c3fd4fc2223dbf56
2022-11-26 05:21:02
0
62
eb514da9eb06775b1dd5a4865951647243b76735764aca8e8b085e4fcf9a131c
2022-11-25 04:10:45
4
61
ac241463785fbb8956a4d0c1b47de465fb995234c3975126b39561433608100c
2022-11-21 22:08:21
4
61
6ac435a67eb247caefc732990e5c309f3094a8b4efe4e3ea8e97774e0b072475
2022-11-21 15:07:44
6
61
c1619258c883ba632894dc9427250aac3d638d3fbe71fc4e2b38a350adaa5a46
2022-11-20 23:58:14
5
61
8e545b03236429055c2dc1d2813f57e4fbc52731bdbd3934ddf824c2ef760f57
2022-11-16 21:07:44
5
61
7b5fd9d8b86d2e42893f4372992699eabee96b61e939f68799add921ba58be92
2022-11-16 21:07:32
4
61
295f385ff62efc8e10b86b11b1b029efbe251f88b0864c166ef572ba052e210b
2022-11-16 18:24:50
3
61
4b027027a90578a1c28a770ff8e8648169a213c8114c713097f7a2f82b05668c
2022-11-14 10:05:10
4
61
98f319f8a003dfeada43acfd4c7f8c235d5c89248aff04744ed12413459b1845
2022-11-14 09:35:08
5
61
71949416297e4182c7a0f22b2ff3a9dfd32bd163b885398a27591a39f691201c
2022-11-07 15:35:28
5
61
13cf69e3703aa0131358159e16b5d62734b471d4d4f24b4ce353c297a3195f12
2022-11-07 13:13:45
4
61
64ed5e78801312d1f8ae19d730d2cef8f9641439f64106adffb34d1c08870d63
2022-11-07 13:10:37
4
61
0e8839177907cd14ae00165fb8d5b8fbef90da5d1416b73325fc43079acb7953
2022-11-07 13:08:01
5
61
5bfb1965f6275b2c21eee520670259c7ba629e92c1e814bc8ca9188207b2cb59
2022-11-05 22:34:27
5
61
1f13a33ca7b8d8d30e4c4625d4a61d2edf57f4c972d9da3c7c929476ddc5dd93
2022-11-02 22:05:44
5
61
feec1079f52a9f0d3bf4a302adda2c3ef6804d50a06034ca455b30399e9baa6d
2022-11-02 21:58:19
6
61
b1ca06d34a3cb3ccb3b5760395de2072bb7420c47ccfd7e48cc1e0971b1f14ab
2022-10-28 03:11:25
6
61
c7e082830f1c6dc069263aab670523db975d0071df7d6ff67b453577cb5b36dc
2022-10-26 14:19:16
41
72
1f091d78f6dd93348b935760d4a1c260fdf889828cfcad707c53d038a2c54715
2022-10-19 15:34:31
11
58
61917eca9fff609430648342fb9525d7285d1199915a199d624d534770323910
2022-10-19 15:25:31
11
61
11de69d50b0e28cd13465a8d67a9e934f2422124e5ca5ab21483f7a8fccf0d60
2022-10-19 15:24:10
11
61
690c5bd69951dcba9c442265bc38531b7fb67c3b7a96c6635cba6a75676c1bdb
2022-10-18 23:46:44
12
61
eeb76d89b74cdcd8f91bc69831dc08a1b39782aef0ef220a8375edf89b0d304a
2022-10-17 13:17:27
5
61
af00dfb732e2272da610ae064199304c3499660507446989948a8a693ada3f1a
2022-10-13 12:08:49
0
66
e87af4dca2d040903bd158f6395fe1b41cbeca934ac5582ac3d0c6a0e9716a62
2022-10-10 12:00:44
16
61
d5ee3dc9b3ffff3765259d91d48c3561292fd1da288e9a472be8f8f8fd20a5d1
2022-09-20 23:42:35
0
55
0edc2f0392d7616f7a85501b0031c4ebe07bfe20f88ae22cdacda769ae3c2244
2022-09-10 13:50:17
3
59
f59d9aab120c92bb4f8f7ec2dbe9897ee6a49befa9f4c646c1b0e5c2d0f36a63
2022-09-08 11:15:17
29
61
b5467fd519696c4fad76935653a2fe1b9fdda647c93543be54701715b7039a67
2022-09-08 11:15:09
26
61
098c11ea4f1acba35c7c6c1fe8dc40db5386f0264d40040c21812197af2a3723
2022-09-08 11:15:07
24
59
b84c2321103515cbd77331796398d99ba1f28363534ea598bc6de47f01076590
2022-09-08 11:15:07
27
59
3a4b758e90dadf5d66bf74004cf690bcca200457eadb63425b47f16e3bf04f91
2022-09-05 14:50:06
3
59
77674bec24fae95d4563aaa285667ae1797c1249cb1fe67c98e9b42efdf36ef8
2022-09-05 14:47:56
0
59
3477a61c0c576ef73703688b89f2b6af76467a57f32f22e60e04fe28119ed000
2022-08-30 04:30:58
4
58
0b5880e34e81396221e6521dbd6c4c5b3529cf675a02bad7b3d95726549e493a
2022-08-29 08:51:36
6
58

Rule Matches per Month (last 24 months)