SUSP_PY_OBFUSC_RevShell_Feb21_1

Rule Info

Tags
['SUSP', 'T1027']
Name
SUSP_PY_OBFUSC_RevShell_Feb21_1
Minimum Yara
1.7
Rule Hash
337abcc8e5850d9d095626c62904d9b9
Av Ratio
6.78
Score
75
Author
Florian Roth
Date
2021-02-12
Description
Detects indicators of obfuscated Python reverse connect shells
Required Modules
[]
Reference
Internal Research

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
9
Suspicious (< 10 engines)
30
Clean (0 engines)
14

Rule Matches

Hash
Timestamp
Total
Positives
VT
68d97376da3fc2f237152465e8913f56cb00b3fc435bd3ba7c0d7e1c95c55c36
2021-06-12 22:35:53
57
1
7492a5047bdb49ae7159ee38a0a5653b1cf8b47620c63c7469c4feb58d7cce9a
2021-06-12 19:34:20
57
1
1d14ee80c1fb787e80d5c244c224c6c11b750ed161899947ef19743b599d2051
2021-06-10 20:46:58
57
1
1aedf6683f584bdd538cb09f27c88ade438649a042c21ba5253f8bf53aa81257
2021-06-09 20:04:46
69
20
0af5198da75d8a50e284968af6f6e8181f717cf09546418240e4c47d5c1dd81a
2021-06-08 22:08:09
57
1
dc13159973cf31f78f0b1bde88685f61172c57dd027b74d1821d235f0b7f56a0
2021-06-08 21:18:09
69
8
f947bd476756788c5443f77a590f2a57653bd2d4cb95e59026fb76fa4f5ec237
2021-06-08 14:18:39
58
1
390c5d092052aaaef75aa00c79b4e9b07007881c4660b9270bd2dbc4cb79003d
2021-06-08 12:33:05
58
1
0d68b005168ff00fa2af8a0894fd3ac6762c1f603de6cabbb0a77aa23cc0c797
2021-06-08 11:48:53
58
1
a66ad5bd3bb68a288aae3ffc53b1dd7bedf5d56f555188be2484faae5a37e77b
2021-06-03 21:39:50
58
1
a5d4ae7f7627a1f73e6f150280125c28ba203e3cc4d3e1faa1179d342339505f
2021-06-02 19:00:02
69
9
4e612e5e45fa1ac8f498f50697ca83df6bb9d2514e179db9daf697e9c0910f0a
2021-05-31 23:29:40
55
1
f457b7cc90fd93d770b67317dd9ef511948b757daf7f08a304ba1ef8ad860955
2021-05-28 22:55:05
58
1
ff869ef3d6b6de19fe57643101de81a5edc2b2d8b6d19a0401327807d8432fbf
2021-05-27 23:03:17
58
1
432469f64b48312ee9fd5a7c1d8e314145b9704229c555a41df5cd6d6021817b
2021-05-27 20:36:30
33
0
2fd4495ee1944db18f2d780808837b2c2ae00848716b5fd4a3e4b09a29803e78
2021-05-27 00:03:08
58
0
e0c3ab6a0a0b4ee075c7404c1bc618c0c998a10904d1e110fb26660a70b78fbd
2021-05-26 19:31:50
58
0
e544c2ab97f2db9cb54a94528ecf4b5abfe5548b435b0b4edf994183775b13e0
2021-05-22 15:34:43
66
5
37b33c6dbe763f1f2f3d52983a3487d0319efc6f4b5defff5ba42c61a4a499b6
2021-05-22 14:17:17
58
1
4b6f217074a49ed451baf428751cd36d9c0348bd1b93445a3d9bbd8e1bb415ea
2021-05-18 21:21:43
57
1
18fbc114cc786a054ff214c66c7509b956c056d078f1d4c9a442488b94c28336
2021-05-18 20:19:13
68
17
d0cb566e257f97184dae70a5721e043e728fcf405e093d16555403839a942f23
2021-05-18 20:04:45
57
0
c303faf9a1e87b4b5fc059cf7f294b93887919d22e3995f9330c01a53dbff6c9
2021-05-18 16:57:01
56
0
9902c0c40680273a75af2136ffac2195b07a278b7443338ef857d7cc448f1568
2021-05-17 18:57:54
56
1
68b59673db15ceef1a3d2340eb521ce9d99906e2780cf86f00a389764d0d6c4e
2021-05-16 00:33:45
68
34
6cc902478649315126a2969f3af42842f8eef62bd3a786faf94cbb1938035339
2021-05-15 21:09:59
61
13
b515716d306bc491af5d257aa5775dbe326b9b103f820f7a7769c807047b547d
2021-05-15 18:15:33
58
1
68ba83b57a2fa5e3eabd35baf1803eae0ecd4590790117f3d191e03b07d9d8dc
2021-05-13 23:42:51
33
0
31038243cedcccebb50aee0094ba43b046d8171cc0dca167df9a0d4583b41029
2021-05-13 23:33:17
58
1
e3cd22334eeef60af52401ce20f465789a81125c714d230625c7c172c1fc69c3
2021-05-13 19:39:40
58
1
df4a7a0dc5a53ee186bd99dd91f4399d4ef626f9f50ad513d44a5858d8873f76
2021-05-12 22:41:04
50
0
198f3c00abb425fcf889712b4957ca5ec106ae8532dd60ec7e676918cc7a8cf0
2021-05-12 00:39:43
57
0
743f0f9edaa328473d221d5cde6aa7ed6fa92b657e8dd9f44de3143a9a74c58a
2021-05-11 23:53:00
58
1
c8a8b00f201c934a2d26a7182772e5fefc1887f5a50345bfc4d0718f5190425d
2021-05-10 23:12:09
58
1
c696b16facfe3d26ee97384af77db636ce9ac0abdbd5131e878e4e2436317a1a
2021-05-07 20:45:31
57
0
f38e73c2eae7c8cbc9c238a006638cedf18824083007a027cb8a48577ef1f63e
2021-05-07 20:12:16
57
1
a98ff6ca470c39b24c56ab40953f339ec20a6171cf9d16bc09c1dd9be345ecdf
2021-05-07 15:18:25
58
1
bc99775aa3d86290a7e11df65794c361c55f753c45093e079efc27776a4b1dc1
2021-05-06 21:39:08
68
12
7d60bb4e26e505b3cf6bdb509b9b53c4f7f8556cf82413c83c0300d9bee5361b
2021-05-06 21:05:27
57
0
b4579d3e7e62e87c28c9a7ab24329340badd299654eee9c58971790eda3bbc9f
2021-05-06 18:21:49
58
1
8932e09b0083851d5016c35d0ed004d299dda65c8d5efe07476b988e21b44dde
2021-05-05 21:16:49
58
1
2af29448e97b92e4c5e3a94d4b11fc17e9f11e988ebb142510f062ff567d71b8
2021-05-05 18:37:48
58
1
a1915352473be07feaa6a43cd8e504b1efbab7c42823118b3d2d3e1ba15cf64d
2021-05-02 18:58:25
68
8
b51c35a72082fec2a70aa89c990e9a7aeec5d3fc2719a23ab24aa1e09017ef66
2021-05-02 18:34:34
67
15
337bba03eb65341578241be324a63e60d589e339bb63bdf9d1f3510d7aa753df
2021-05-01 12:59:51
55
0
80f70e5eabaeee72ad94f2266c5a7c44078349b46206ff99cce8b52e1ab3f4ab
2021-04-30 12:11:51
58
1
03bd05658d9b72239a27b9c4610e973dd2eee2974a6304852485552778aac3b7
2021-04-30 11:15:20
56
1
96ea1fbe78623c84294eb26d420fd73730a0c9848eaf7724269c3ed182d63aa7
2021-04-30 10:49:28
68
16
b9cf431d51b36f10212e93f9bdcc0374b88f1c6aeb397e256cd08b7af45454bb
2021-04-28 18:49:14
58
0
858f39302adde4cafd9f3f3b793e1ada251adb333ca5288764ffbf0307b608f6
2021-04-27 09:57:48
69
24
24c0a0f3890eced676dfa908f1cb4e8774fdb2634a27e031e677c090d2b4a669
2021-04-23 18:12:20
55
0
010a3768154351325354fc8e09c0db779ed238e644285cf2673620e50c739a13
2021-04-23 16:04:46
69
32
04a4f3b71a6ee98f0729092158c07bad380ec933268544a321da500660cf0376
2021-02-12 20:06:05
58
0

Rule Matches per Month (last 24 months)