SUSP_PS1_OBFUSC_Through_Cryptography_Method_Jun20

Rule Info

Date
2020-06-12
Av Ratio
4.43
Rule Hash
ff4f0b6e776142401e4e1ad3fbb66ff3
Score
40
Description
Detects a suspicious combination of functions used in obfuscation technique which is also used by goodware to protect sensitive information
Name
SUSP_PS1_OBFUSC_Through_Cryptography_Method_Jun20
Required Modules
[]
Tags
['T1086', 'T1027', 'SUSP', 'T1136', 'OBFUS']
Author
Florian Roth
Minimum Yara
1.7

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
0
Suspicious (< 10 engines)
8
Clean (0 engines)
13

Rule Matches

Hash
Total
Timestamp
Positives
VT
b85ac5bd305209817faf0786e44e20386918a0074eadde7262bf3db8668923f6
59
2020-10-21 04:08:23
0
95628d1e6da8e3df82cbcf3ab5020ed2fd7ecdcdbe9255dedad9743db39dada5
60
2020-10-20 21:27:42
0
85497df7e573ef11fc80e8f57b8a69eb6a467841deb641e38d6211e84e8e8a28
60
2020-10-20 18:50:34
0
65c78b697ea0639bbec6dba60df755030654eecf62532c7c6b64cf8e8f8397ff
53
2020-10-20 12:47:02
0
4db6ebf81327966fdf234ee368f35acab5b761be7933fb83cfe3d85c53d1065d
60
2020-10-20 08:33:33
0
28c57783b73946e60ce02aa982b001a676f6ab69818f63b8e645d5e766f8133f
58
2020-10-20 01:56:31
0
120449ab3bed1a7205f780a87727a53a28d99c9b2e1c0b6703ed43effce3aa43
60
2020-10-19 21:46:08
0
924a0f98ae0395ad78f40dabf479ced1348d67f3607898d7e1d8389a414b263e
60
2020-10-18 01:41:38
6
284dd516f2b8d8a81113ab82f1def038579562aa75b867823e97b26e1aa92aea
60
2020-10-15 17:56:25
0
43eb5fbf6f8ecf49f131f58c0e0b7afc22ecafd0316cdd0a27ffc18cca19db6a
61
2020-10-15 11:54:52
0
202e481778ca7a2fde52cd689219205b9f90847da59423fc1a9c7c45d7ac5610
57
2020-10-15 10:20:56
0
3b8ac53b45bcc7c554caac82d01ef415aa438fe22f2715049a3ad5f2bcc38bdb
59
2020-10-14 03:57:50
7
cde035abd4e2e2810fb774704308b4f794e9053a648a71d47e403d42d585da0a
59
2020-10-14 03:57:35
7
dbd30e8420d959a189e8fd7d4c0708f89c706ab858bc57f64382300ecb2b1b90
60
2020-10-14 03:56:33
7
f161bc4143ee3ba8dd9255129e7dd94b0abf8d7e7fe5eb9c5141cfc3797e8d8b
59
2020-10-14 03:56:29
7
952750c70cdc9b37efdb65d57dcd6b2254060a60a26bb825e6c33e592c7a28fc
59
2020-10-14 03:56:13
7
b614d56d8a2485c84dbb961f0994a18b03af82e89f355ee42c787e44ca8757b8
59
2020-10-14 03:55:49
7
b1dcb62305db608011d8dcd26fc4e9a1bc7215596b486cacdb0c91e00b39337e
58
2020-10-14 03:55:49
7
155fec20a1fab0097d5eef26c354d4ddb888bc13d68d297e2f5a6c2f54c43f9c
59
2020-10-13 17:04:06
0
5f27f196bbe0acc622f971f9f68fe7189de88e7f3df768b14972a3ad65245840
59
2020-10-13 07:58:23
0
6c80d5f6480212c37ced71ac92aa5cce225ee8727ee65e6ab4e8265b1cf1ad1d
59
2020-10-12 19:18:45
0

Rule Matches per Month (last 24 months)