
Rule Info
Description
Detects patterns found in small Python reverse shells
Reference
Internal Research
Score
65
Date
2023-01-12
Minimum Yara
1.7
Name
SUSP_PY_Reverse_Shell_Indicators_Jan23_1
Required Modules
[]
Author
Florian Roth
Rule Hash
3389e42dd716f0c80cbce5bf71ddcc90
Tags
['T1059_006', 'SCRIPT', 'SUSP']
Antivirus Verdicts
Rating
Number of Samples
Malicious (>= 10 engines)
3
Suspicious (< 10 engines)
13
Clean (0 engines)
27
Rule Matches
Hash
Timestamp
Positives
Total
VT