SUSP_Small_ISO_Includes_Rundll32_Apr21_1

Rule Info

Av Ratio
9.56
Required Modules
[]
Name
SUSP_Small_ISO_Includes_Rundll32_Apr21_1
Score
70
Reference
Internal Research
Date
2021-04-28
Minimum Yara
1.7
Author
Florian Roth
Description
Detects suspicious small ISO file that includes rundll32.exe
Tags
['T1085', 'FILE', 'SUSP']
Rule Hash
3eccbeb2b321b20b0992a39a969e5676

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
10
Suspicious (< 10 engines)
30
Clean (0 engines)
8

Rule Matches

Total
Hash
Timestamp
Positives
VT
56
6e21ff149b249c0aff3988eb9aacfc4e9db78a4d14de0310395a2f8b77f5565d
2021-09-24 19:46:59
1
56
734711e6a69b55f887e9e7cb6dc6369ce618eb19227c99c168be9fcbca4ce948
2021-09-24 18:22:03
3
58
33aa62f7f5bd608511de14de1c77411e713ef7d6b8b333bb340c197da52b6e84
2021-09-24 16:18:39
10
57
db8f640d5de0c29cdf0ed0cf8ebe14f7c511951466fae6165efadfe88f7fcee8
2021-09-24 15:57:46
7
57
7864d3061cad9d74fbdcee42407751c47e3a57949985f64ae8c3f758de09c931
2021-09-24 11:35:53
2
57
abc2f1ea117d660f9402a1a22df7bef012c23ac3832924ec0b5fa5b11dae5dff
2021-09-24 09:57:14
12
55
9f8be9efad48de663087d77f452a7a12db3d29f7d63a24e38fe1a96926dd5322
2021-09-23 19:44:45
1
57
9e8a158b858944abefa5aaf9f5930e22a0ff603324216c4034288f032fe4a29d
2021-09-22 19:06:04
4
57
e4efba545197be1182a040699100c6abea9fdb89eda46e72a8b6bcc57fd64b3f
2021-09-22 00:17:56
5
56
578b741306b507b9b84cd81c4322943527fe3ff341a08cf9f466b87f0b66c815
2021-09-21 23:29:20
5
56
7055499678bfc816722f33fe83353eca6e19acc840935e85b048aa2b7d526bf2
2021-09-21 22:43:30
12
58
eaa13d98417b16316cc6dbb4238f244dd48e785a04fa49094337b59aac7e32a6
2021-09-20 09:37:28
29
57
be6df812874d7b76cc1832f232c47cbd17f9eea195042b9e5133541143ea90a8
2021-09-18 02:03:48
11
57
57c105f683d2bba24b749d984ce44999852e32224698b0cbffe8140d3100a19c
2021-09-17 08:45:00
6
57
71ebfe254f38f1d4255f95accc84751d019a8a52f6b8c569f7941f6207a00842
2021-09-16 17:33:38
3
56
2c37133793fc33eea69e93a498be2c97d4f6c7b79df53c9723261ff9dcb55634
2021-09-14 01:44:12
0
58
ff3a894bd66a5f372ffe5b47351d2d2c967c01f240ef052065f03e4a30ded4ba
2021-09-13 20:18:12
12
57
5a2dc0abea293ffb02f5162df70b1edd9d7488e3d3851ef41a24615a9af00ada
2021-09-13 18:20:48
3
56
46896f5338d2ec903d77f81f28abc79ddb2a271ebe8d277fb75640858486ec66
2021-09-13 10:37:50
1
57
197e5b24c57b7f58a464a5d9a35b0a42a1343820976fdb571cf542ba64e927ad
2021-09-10 15:42:08
3
56
b58b27ea9b3a38c2472d206e46c1fa711057abb186a0496f12d291c87239ab09
2021-09-10 02:54:48
0
57
cc62d9bd5270466e09ec5365dae1699afde9e4c114c4eefe5399c5317f616559
2021-09-10 00:16:15
2
57
23e6f027da67a418df9c72d06b8db873645ee58ba5752a1a389b4d4cff624096
2021-09-09 13:27:12
1
57
ca0ccb8fa82d006765d547814567d92e9cacb027897884a5d0cfa10a6fef9d9c
2021-09-09 00:16:51
3
57
389eea666a84c7f519a2677b1c5296889c53be733215f11764d6bebb41cd321a
2021-09-08 19:29:05
2
57
f3ea48a2b8c8e55ef0b178a89290dfbd124bc058505d5d15dd6ae5782fe9fe0d
2021-09-07 23:52:12
1
57
34c80091408862ebf268716b12ab62b9fb975fdae72d69bfc5929ce1342439f8
2021-09-07 22:53:26
1
57
8326943327289a1e0d1ffd3e8a7538a8ea9e5b39d8531c7308419bf62f9c7c07
2021-09-07 15:38:56
4
56
f25f0fe4be4d95dec2b1bf081f6f5f337cd44b30f1679dc9123ea1a5885d3786
2021-09-07 05:21:29
2
57
35337f1102c63de3b1c99fc8a0952a2779f85fbadb2a688d43c6e31191d49e27
2021-09-06 15:56:55
1
56
dec6e10d0f7f99a56e931f4021e6407d275d4e5b20bd7c80d3504684e56a9e36
2021-09-03 22:08:59
2
56
08ed91d5f316d51210f70284f272b3aafb378e49885452d8e20eae4f98f70666
2021-09-03 03:35:23
1
54
1de937b4a50f77cc248e66f4a50a82db2f0493d9f61c3038f22b04b56b5acb4e
2021-09-03 01:41:52
1
57
f284860580f7e24edc1c26cb4d0d9b6e422ec9c43365880e2cc7daf159cf7fac
2021-09-02 05:22:36
2
57
a1941c406c934be29b40186aa08022ffaf787d18eba7a2c018507297dce656af
2021-09-01 04:36:49
1
56
2b467592fefefb1cced48d543706016e346a30799e6493d5862ddb1568482e32
2021-09-01 04:06:28
2
57
df08e48081ee4817f0f5fa67750b1591d41a542f2811cae96feab14844c48236
2021-09-01 01:09:40
8
59
89016b87e97a07b4e0263a18827defdeaa3e150b1523534bbdebe7305beabb64
2021-08-13 20:56:07
33
58
3e8bb8f7770b36ed0edeb65a5794ca901268a4092f171bdba28d58f039bdadde
2021-08-13 17:05:39
0
57
80921712a450c06e164befc436610a980133b0e77e87c2e9f0d6bc3f15f46498
2021-08-08 15:13:30
0
58
09b553a326d6fb7a2fd79c1c2994e22bb596f4e382c3ffbedd5e1045e70cf0b7
2021-07-23 07:54:51
0
57
d0b50e16aab0184c2188d3c730c3084beda93a03117ac646a2bff8152ec36cc0
2021-07-16 20:14:12
0
58
9c229a6a188bcb51cd398489899c8cf270d41d7e9dd0d784f84583adad0035d4
2021-07-16 17:24:58
0
58
6e2069758228e8d69f8c0a82a88ca7433a0a71076c9b1cb0d4646ba8236edf23
2021-06-01 15:22:01
24
58
f006af714379fdd63923536d908f916f4c55480f3d07adadd53d5807e0c285ee
2021-05-31 23:49:13
25
56
806428f700a3f3a85eee3ce903062b1d8e3abb2979dccba74c2209b3581d3dfe
2021-05-18 17:57:08
0
58
e41a7616a3919d883beb1527026281d66e7bcdaff99600e462d36a58f1bdc794
2021-05-15 22:16:26
3
58
108a982eca4344fc6017aa457fd6c4b74555bc3be33f84dcbdce5fd1837ecea2
2021-05-05 17:32:13
15

Rule Matches per Month (last 24 months)