SUSP_PS1_Loader_Indicators_Jul22_6

Rule Info

Minimum Yara
1.7
Tags
['T1059_001', 'SCRIPT', 'SUSP', 'T1086']
Name
SUSP_PS1_Loader_Indicators_Jul22_6
Description
Detects unknown PowerShell in-memory loaders
Rule Hash
16e64a5b6bcbb1cc8edac60b804b3570
Reference
Internal Research
Score
70
Required Modules
[]
Author
Florian Roth
Date
2022-07-22
Av Ratio
10.29

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
18
Suspicious (< 10 engines)
11
Clean (0 engines)
30

Rule Matches

Timestamp
Positives
Total
Hash
VT
2022-09-28 22:10:19
0
60
97713f7e7113b4bfd84497215f194d7c3b12ac7c1487dcd792d92bc7df7e5702
2022-09-28 18:31:47
15
61
a53ddc23e20736ede243cf42aff954f221d3a41b821491ea8518c2ab63ee7ba9
2022-09-27 17:09:54
0
60
751f08ea76ef6f6b0ed643c35fd501b0db766e7fbcb7d70b7414b9fe735ac7ff
2022-09-27 11:48:49
0
59
eacd4eccb1742058daee969d045e374c3162639cf49014e6f57010d1edab37f4
2022-09-26 14:39:14
0
60
ae513dab28cf1241f2ace262c1728160b6ac666c17105115d0233b882defb076
2022-09-25 23:25:38
0
60
5c2eb97374062889a824fb78fa9a33ea0c50bb3e986527dfa8295ef7d27cf86c
2022-09-25 05:38:26
0
60
45507974c652650e1f74cb2fe6c91db5ff57beb467731772a5087f1b4df891cb
2022-09-22 14:58:58
27
61
d5393620b85f617d5ab8cb52caa24b83111e5c459b39653eb8f9223c2ad3a42b
2022-09-20 13:44:23
0
56
2b9caa4342213876add4e76e511db15a16c6cbbfa3023dc5469f4c873a434fd0
2022-09-17 09:05:37
20
60
bf649daaa9bcdcd625b81956a3fb77f019540ec50fdc4f339831328981cac006
2022-09-14 10:49:29
2
59
3138666de47cc313e70b873184490a74abed7ebce18d546a78b18a2d4b065d4e
2022-09-13 23:19:42
0
59
6a5a154efb35e4afb96a1a9e73229e012981c9bbc9cefed2f6f032efb12709cd
2022-09-13 19:28:03
0
59
3cc82b4be3a351804d1e47b07824bc4222055edb92e58c500bf2765a8cd28e84
2022-09-13 09:18:54
0
59
4ff4c551d6c2c83f65afad9d8c708eda256fbcf42b70f10c48f8423d19759adb
2022-09-13 09:16:18
2
59
75a33f1e602b677cafd11d572c3251cbab3b070955d44865ef242fe7b3e27146
2022-09-13 09:14:27
2
59
ad7eab7283051941396265f5cb279cf4f564c1995dfdb53084c3c873f79c3ab6
2022-09-13 05:46:32
0
59
d269174a853ab07d76c3028abaa8db5638bc90bd839255d4ed049c7b937947c2
2022-09-13 02:44:22
0
59
e9bd86f61d84cc9670bf6a1084d891287e57d7418b014261f3f0f803a0ab3a62
2022-09-13 02:41:45
0
59
539bb7c9cd88e428a8d93232b718521e67ceb1bb7bbf14e660e78d04c02dd34b
2022-09-13 02:38:12
2
59
0d3a4782668be54971e438ced0bc92564d2b96889838cc9071e078212e563547
2022-09-12 19:01:16
19
60
692fc7273b22612320784c1899050bfc4c7e5cb9607eef3a65d413a1e7bee4e1
2022-09-12 16:56:48
12
59
215b281acebbf49e43e264994b2975bdd5cf9e502446c3cbdf43df4e04641370
2022-09-12 10:44:46
2
59
9cb3f29de65204edba068bcfa1919011814ea93e6fa0704c6aa694f9adf5a66f
2022-09-12 05:59:10
0
59
91a15ef2841f78feda97c7750eefdd52a5ab04dca304b03d74903156935e2e29
2022-09-11 22:08:28
0
59
ebe18d654385b4274b98a4c8fb3066b7112dc22d2404ed4430efd213e34c01ef
2022-09-11 22:08:25
2
59
4bc134548687299de37f97a4965dd9e18d373ed65b56d96b6ad30a4e9088c496
2022-09-11 22:08:12
0
59
8bc8c6b559241493bb21bbaa10a4c87cd8a3fbfa2521f7e915621ffda5495fca
2022-09-08 19:30:06
4
60
0ff4a93d5a7756ac7a9a27ca63e38f378926ab4fb657f8cec461f293711e4df8
2022-09-08 11:08:28
0
59
309c1aa87223ed6fac2aff1fe1b1bc48961c8b58021aa222085f642501a60f70
2022-09-08 01:21:21
0
59
7167293d26239e68768ebc9b7aad005d63b425eb6e6ad882f7735b097e9777fd
2022-09-07 23:39:40
0
59
f3b0a2cb23674ea0f984f0081247bd47f3ec1f3172544e1a5f4ba2b4fc42d2ba
2022-09-07 23:36:12
0
59
dacb70432e879def44efe8a169fe500825115e7209bdc80851c0a21d280cc927
2022-09-07 23:33:26
0
59
86882ab6a218f7522b87cfba7a269f5714b8c5ca7bfbd7606d62cbf7426c5863
2022-09-07 18:40:17
0
59
b8bd04c091dcc243a030344e7a2f0e6003ae699ff876f24cc964df29c255204b
2022-09-06 14:11:48
17
60
eca261e2a1b1e558c64ed1814945f3b585ef5e37ad12f0dff9448bc969925e4e
2022-09-06 02:37:39
20
60
2b1479a5a53511ba0738eaef6a6e5b46f04015c43244e2c99f1f38a6c42cc671
2022-09-05 20:11:06
4
60
a16762f7bc77d0ebecf6e1f1a39020b1becd0087828b67c09422b8404b017194
2022-09-05 19:16:12
0
58
75940a1af0b27176bbc8adabda4b7f4b66268108419758b07ab46275e06f2ad4
2022-09-05 15:01:50
0
59
b12bb14ba3a3aefd88042d4f0628211f63fee6f87d06bcd61a257e2e5682d0bb
2022-09-05 14:57:37
0
59
d04c9af92d0de98a7271d7bb0ff7b31708eda905430e04c7d410a82a944f803d
2022-09-05 14:32:12
0
59
98a6391159113faec46d043d96d652bbd13b529bba260e08177041d9993f1aa4
2022-09-04 00:54:50
0
58
1d7ad546bf12da13b52ba0f169d8d71367486926bf96a782aef22d7afba97a7a
2022-09-01 17:08:25
0
58
da31a5b52b786d859e1582d29f27092311e8ce777ce98bb05d453802e5f2ed74
2022-08-31 01:56:54
0
58
ed10389bf0661a71a777be41805f85dbe24f7de719063b0e46a784069fd95f1d
2022-08-29 23:37:47
19
59
b73f82fa3e9af1cafd490755a8c35e5ff94f7478a19ca2a193c8f37d29b6774f
2022-08-29 23:36:43
20
59
7ff603facd621afa5ece27dba1631fdafa9b3ef10892f82f644ec70b13692f6c
2022-08-29 18:02:11
19
59
70070a2220b4233fa872f5817d8a359c46d6f84946c4cb00402089bf47379530
2022-08-28 20:21:09
17
60
6245cfbbb56ec4932236a7e5d1f8f6720f40a89bfbf3c49f63af5a2c60642fcc
2022-08-28 20:17:59
17
60
1d0c86398a6ba85f359f586708bd142c00aba99ad466a63fdf5137769bcd0def
2022-08-26 19:01:54
28
60
65a34d98e3c101da42039ab5c17fffba40abd38fe52e9a9bdb858ad52f23eac3
2022-08-25 07:02:28
13
53
f9806f4ecb3bf2e61e10dcde4a151fafbdde8ef0957471d42ccc06d923e046e6
2022-08-22 19:39:27
14
60
f940a4ef927897f833881b6d039cb8b7bbfe9dfe54f4dfab8299e10066331f52
2022-08-22 17:39:39
2
59
4cd603a01d6e0ea7e2888179c1f4acf257e61ce7a57aad54cbb87e0d73c73d7c
2022-08-20 17:37:53
9
55
dad506300c1781adfec4f8bb8c7881df3b90b1e76372083908f215bfd14841d9
2022-08-20 13:21:13
0
59
b6edc4cbd9118073498fbb9564e4a081555427aedf699081007dd8b37ca62618
2022-08-19 18:30:41
17
60
06ae3aa88aeb92f8660bee48801a40bd9d4c82810c6fb3932286d41f011c1505
2022-08-19 18:30:35
18
60
4c87feecf70223a337b5548a7b9b3c5f8267a5a1bfdb5530c6ade2f86d315903
2022-08-19 18:29:32
16
60
2c9a42334d872e1f3723744f79aff4ec00e7e0e72f4666d9c016d5b5ef243639
2022-08-19 06:37:38
2
59
af0c08b30cc721d2ce4dd8396b0f14da22c4ab4e73d8072afe450099d2526e58

Rule Matches per Month (last 24 months)