SUSP_Recon_Suspicious_Dirs_Sep21_1

Rule Info

Score
65
Name
SUSP_Recon_Suspicious_Dirs_Sep21_1
Description
Detects output redirection to suspicious folders
Av Ratio
20.53
Author
Florian Roth
Tags
['SCRIPT', 'SUSP', 'T1592']
Rule Hash
7b081b54e5cd6e1bc62c318d1dab29ba
Minimum Yara
1.7
Date
2021-09-06
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
32
Suspicious (< 10 engines)
21
Clean (0 engines)
24

Rule Matches

Positives
Hash
Total
Timestamp
VT
2
f761ffbc5da387255e0bf057beee4c3bdfb47d3f6e8b1f19fad11ab8087d8438
55
2022-01-19 23:46:18
0
5d75a55860fc80193efaef10196ec4abdf3dd703b0e00e9463d8bfca75756333
66
2022-01-13 08:01:13
0
b03ddfe0e8a93d149ad7ee7db2e22d2b489a56755fadf7cc7de64f7bdac57eea
55
2022-01-10 10:40:23
1
24d78f7cd9e352eead96a03eb6a3558e936b8312a15d67ac4a8dfbe886a498af
53
2022-01-06 06:12:22
10
91a61a522510c428702774d01601bb0016599380016f9235915031bbc9b99a65
58
2022-01-05 07:01:15
29
621c65921a7921694095c3dec2ba598faf0944d69ace63a4857f2087235f7854
68
2022-01-05 02:06:28
12
50401d3cb0de2484ef182c635e3391e892955d739fd9f84a7d6374d663a7cac4
65
2022-01-04 20:27:36
0
f556d1b6f2ec8dd10466f786f70bfaf9ffa18a90e6b51513b8955111a7bc8a51
57
2021-12-25 12:58:39
0
f39ef6c3b4409af91515df55e566c969ebc4c52fab1a0dcb870ec464ab78b392
57
2021-12-25 12:48:21
30
dad92d2e336ef3266ad65fb0ea0ca02fc2d9d9be392e690a5d79a8c78ec0ac73
58
2021-12-25 03:38:34
1
41d36c482530d7d3a3876cb5d8f5e3a7ba35d154dfc0ea4f73f9f8793f92c387
65
2021-12-25 01:17:25
0
6c43e709d55f1cd97d005be91ba1a5063671cfa9d4b53382c8a7038f014cdd58
57
2021-12-24 23:18:51
0
542c2c187ba73f3ddebb47514a63c95bd688b41e8d96c778bc7e071ff22a476a
55
2021-12-24 21:17:54
0
474ecc6b606a116b7529b1a9c7ae4d327607b91b30ac7493c22437744d7b22e6
56
2021-12-24 20:14:08
26
3da3e7574f1184199b48b7d63576ee2ffe92825d8989692de22b33e5df67bf44
68
2021-12-24 15:21:37
0
b74d7e3096956fd4bc7c929c2b482969f13a465058276ee97eb76c1d30529aa4
67
2021-12-24 14:45:37
2
c66a79726a52709cb4ceb004f0b2dda9d7159aa04678e002d9be27fb7d887a3c
68
2021-12-24 14:37:12
2
c45986288840a01919c3b744499554d5a0608a2a109de0952b80303923cd3ce8
68
2021-12-24 14:34:45
2
199c57a85711459c0b0fbc8883b19829cec8c64588f50bb4a6b2611f6ad4d62b
68
2021-12-24 14:00:36
1
f187ab7396fc3a96e9549316af3e8eaf9ecdca41adec82d98ca52e67974811a8
66
2021-12-24 13:40:14
0
098c87536e080717ee38d58149c44e36bcf7e898787ac7090a01f5cfede578eb
57
2021-12-24 09:23:57
3
4b5eb7a3a200061de97b9cf7470b06a05982d9298aa2dbe11692e5dded99f4a6
68
2021-12-23 11:55:01
3
8507a3137158b219efc75840228d64602aa39f099a439cffe734113b16083b09
67
2021-12-17 17:00:46
36
ee19420b350a8a2703dd38384f4ef72d92d0bdc90f8ad84921f21b07272723a8
67
2021-12-17 13:49:44
28
77ca79d7ed522a7d221185d9543ef3a912c433952d950471b7866e98ae436d42
68
2021-12-14 14:57:44
35
59216e4f11d9aa5cfac6db06ee828d54450493fda3939638714c1167bd7d79fe
53
2021-12-12 21:40:15
0
032312ee4863975381fe98cd327f95ee28c6ee64b7a17d9e2556a72eccd65558
56
2021-12-12 11:58:50
1
121cafc33fe8c2f2a7e6222cf5d616cada5390db33c6fa77722432cd9eba9df6
56
2021-12-11 18:57:00
0
f24485c6001b09b035b87e0c6d50908bb06a94bc8100dbdb2bed4bad93210bb6
56
2021-12-08 20:32:44
18
d24d19a09fb3fe05cef9dd75c9d03da051f8599c540a1fc8c68d2ae679cdc2c6
55
2021-12-08 07:33:11
19
3464b71ef33210d4783041cba78499d42c0560b9915d65e5559d3e693850f5e6
50
2021-12-08 07:26:57
0
ecb2457ee4fc5b8831e22e564c507ba27daa54c7e3811e5f7739ef2bdf65031b
55
2021-12-06 20:05:47
0
1cf5ca298c712a85363ca2d8ebdc9ebc66257fdab63c3900a37fbb0e154b9d2b
55
2021-12-06 20:05:36
0
a5f5efc0a604086976111a8f7bab8f8311b2d79093e02b226f6925632cb1a6a2
55
2021-12-06 20:05:34
0
e5dd242214f25b87a0e4597f678bf76d9ac8253f553fc73f3b5d139b23b86c39
64
2021-12-04 01:15:23
4
a572394fcf19b89229c75ebbd784c2598c9fb11855692c6a92a821350800fc0f
65
2021-12-04 00:09:35
2
137dfb652ef1394a923a8ddf513be460da2f37156e23a5157f2994346a8311aa
64
2021-12-03 17:03:46
1
f316d262906bfb2809ef654a4d45bb9bde876aeb8d16b83a3885367ab75d7e88
66
2021-11-29 14:58:20
0
ea4a626f90932447ff11d73eb2b05dd48cfa97483c0e795fbe215d36dfe1f97d
56
2021-11-27 16:20:04
34
09d476d449fd7981639bf994a8a22445aa515c333bf1e287c82a4e37124df06a
66
2021-11-24 23:42:20
15
b51a2540f46364f951f2d02ffa81aca879cd88377fa29d6ec88b2390ef09c547
66
2021-11-19 13:19:08
6
091cde4c9a8e7dd2bfcb6d1854f724f5ec4e47159ec04b8311f44d30a996e5a3
64
2021-11-19 00:39:48
36
7ac7480081991544654a945596c2e24adcbc8ba406b618be3b7274c9cd4bcf14
67
2021-11-17 16:35:20
16
7a3691ae69360fac5832e09dd746bfa616871e1d22a7008c294579cf1f0f629f
66
2021-11-16 04:47:44
0
b58d3751bf49c5e2fc1c02e1603b2fdb24c37434ebaf6e7fddb55aafedc97270
55
2021-11-15 17:18:30
0
6fefdf5bae3d8b50b2223f9b47c89ada7bdfff53c950f7ef737e6b6f67185c08
54
2021-11-15 16:19:49
0
a7a2edb47ad66ad738153dc6886b958b3cf87732a6b191e7fbd033ce92f2a142
55
2021-11-12 15:10:22
27
090847b51902eeb140c645bb72f5e10fa354c03d77c046a750d7c4a12c6d93f5
59
2021-11-11 12:21:26
34
e0369b93f321058aa576a1aeb961894770510a3e78f0d97fe11eb9efad7f2fc6
58
2021-11-10 16:46:16
33
d0ad8e446962c7074d556318072385e9298203baff0aa27588b5542960e89440
57
2021-11-10 15:17:10
35
bf6babbe042f2426b068860dbed267191be37586f535160df7f778e05bbcb05f
58
2021-11-10 14:07:13
32
c0c3d268328bf88f8b318719ebd140b4df82a582f6a588f4f96956a9c647becf
57
2021-11-10 14:06:52
32
4d1dfa0309f1cefcf3b7f50c7dfd07e26de68767cb7a090c7dd935297cd7f20c
59
2021-11-10 03:43:15
26
493eee2c55810201557ef0e5d134ca0d9569f25ae732df139bb0cb3d1478257f
56
2021-11-10 03:15:06
32
43890a1e5ac0cb39b585c42b001b31419f13fc22ed47bd2a0f4c4c5deec66a6e
57
2021-11-10 03:06:51
30
40b14b2bda1d80af1d48a3f608fb2871538df2500df9d1923e9a8b7cbfc824c8
53
2021-11-10 02:25:32
31
2f6743dfee6e5b55a1bfe7713bcc067a01223adf61f0f99e420f4538aa8b5d56
58
2021-11-10 01:31:30
33
292e57ea7428f65b7d529d89f1a251caf3b65192f3af48f3575f147683a69a2c
59
2021-11-10 00:21:15
36
10d9d94c615d8c8fe537111732ac74e863ce11a6ccc55d4ae1afff4495f36b2a
59
2021-11-09 22:17:03
45
5e93d0b660f9123f36f3b18fc596011b105fa9bc409a1e707faf148ee69bb94d
68
2021-11-09 14:12:52
29
f0ba0bd9560279cf07a022b10a3cc323d07dd9195ea4ab6ceab4ce409830dbed
57
2021-11-09 14:10:49
1
098b8dbee97a026d9da03199d8ca32c85a25b7709168cb1ff2ddbe8aaa6ca653
64
2021-11-05 09:40:48
1
574124d56ad610dc1e0138cabc02eca14b24e2aceda99e76fe2a440094d15c36
57
2021-11-04 18:39:07
0
053a2c4045823a06a1c2981db948efdb03da9accf90ff56645ba26f99d8eb6dc
56
2021-11-04 16:15:38
1
e90df98e95cfd4864e3ce516a46a37d1c2c2d03f5aa9837ac7dd9cd72200b6e9
57
2021-11-03 13:47:23
6
8a792176294c61522da696576b1e527ee8bff89acff1fffa322d615dd9545b52
66
2021-10-11 18:19:16
0
c2ad05484da1ed1353f27530632254160e20d290fa04f214264c8da19e149730
57
2021-10-10 13:47:00
28
f338884752cdfa1356b7edaef0d2bccaa2df7feba0a3d7576cb714e16e8447c6
67
2021-10-04 18:31:36
4
ef01ba1467fdcc9bee4f0468031d95850407030244782242ebb3a3d482c45bec
57
2021-09-25 20:27:07
3
97794058baf6d708ac1c1e8dc20d0ed377672ef4226ece12a20d3981d96174d3
58
2021-09-24 22:39:47
32
0be5cdea09936a5437e0fc5ef72703c4ce10c6ceb0734261d11b05b92aaba2ff
61
2021-09-23 02:17:38
0
516a56b4d3f19777a6a845ba55ab78e4d30be5e4d579c0302baaa8555257030d
57
2021-09-19 01:38:31
0
dd2d4026c64eedc6829b6b48e351580594b372c576d202812107a38b260737d5
56
2021-09-17 01:54:06
0
813d612489b94d7f3a3c4e6639cd0b9284ceb20fb42b772e7e01e822be2e3573
57
2021-09-15 18:53:38
22
f82d705ee4385bbb61444ecb3ed76770951779ca357480b9a05d5319f0871c95
59
2021-09-12 09:42:36
24
b2512907af97392b224d7b5748ade4461d9b371b26b38a0cdefa66b8b82e4a54
58
2021-09-08 22:35:39
1
81ae8362875fa49484c1b40ad0ec674ad628e2de361c7fefc6121b4d29eade80
57
2021-09-07 16:16:27

Rule Matches per Month (last 24 months)