SUSP_User_Folder_PDB_Dec21_1

Rule Info

Score
65
Name
SUSP_User_Folder_PDB_Dec21_1
Description
Detects suspicious user name in PE file
Av Ratio
9.41
Author
Florian Roth
Tags
['EXE', 'FILE', 'SUSP']
Rule Hash
e80e1fef972167d8226e727f2ddd2ef7
Minimum Yara
1.7
Date
2021-12-03
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
5
Suspicious (< 10 engines)
24
Clean (0 engines)
1

Rule Matches

Positives
Hash
Total
Timestamp
VT
1
c936361f950ac2e5803557bb28dc2440d0e2b8a9109c4bbd5777d84a340e0583
68
2022-01-21 07:18:29
50
5fcc9f3b514b853e8e9077ed4940538aba7b3044edbba28ca92ed37199292058
69
2021-12-29 08:21:47
0
62e9778957a0bb0c2881f2b72a2b2fb7d72bcebd49cc3e53320962a282ed1766
65
2021-12-24 06:27:54
33
6ffc0da42d9f99e30c599a8bd4bc7dc4b6d54ba8261beefcccbd822b879f3150
68
2021-12-15 18:32:41
14
a1ac13fd23dc8b6291dbf58bc8250206eb3f006af984293e96a0a14ae1ffbdc7
66
2021-12-15 17:35:54
34
b5d2e844eae3aa538970860fb1dc8b440e5fd47dd672c5c09be795ccd7daa035
68
2021-12-15 17:26:08
1
d5b1bc32b30864db05b8cc89861c317144d77005d7f629220b770dc78211d18f
67
2021-12-13 12:05:53
1
43add38af6f1a60df4a4d6c17fa86266021993e157083be5d6b3b5257360adc0
65
2021-12-08 10:48:55
1
646415a3545e665cd50fd2f58f39f89a9bb996f31cf18e4c6fc9260585bfe0ea
65
2021-12-08 10:29:39
1
57b96b97e3bf04b837422e4aa19beb21927002da86b1641400702ad3ffa391bb
63
2021-12-08 10:29:39
3
a9d2257cde89c36aa9f44ee7f8e913ba7bd5949127d55303e1097befc053ca5f
64
2021-12-08 10:29:38
3
b749c4508fc8c6a2be8d5500ef8f4913900c1b4beba96151b1b4824ea5185803
65
2021-12-08 10:27:23
3
17e415e16439a6ccd880c2dda0f593e81c6de4d846287670d55abcbf7b11bb8b
67
2021-12-07 16:39:11
4
6c21a7844d9600ae62f9349baa256d74330a6496119407933c0bef4c30f4fc2f
65
2021-12-07 16:33:14
4
da5b496fb5e44a4e946af2e2f7e3130046ae1c8ff2daf3a51aabd932217c19e8
67
2021-12-07 16:22:01
2
dca72f3387216b56f8de1d8bde8a8da67f71ffe93b2d45a43dce977baa2571db
56
2021-12-07 16:14:59
3
0c88b096681e9750b398c730b23ef0c65fa3b35e30b457e29109da3fc5f348c5
66
2021-12-07 16:13:46
3
e2d4fa353f5f592cb115313f66349bbab1e71715a80f8fb14cec9f56a77bbd4f
65
2021-12-07 16:07:50
3
e9f77a2daed9183abe94c948c8ef1572b4fe43cec2905fcad070dcaf9ed98739
64
2021-12-07 16:04:29
1
65e2ab7d07a61eab83607af24016ba6f76c7b67297f61703b06165fb19c75868
65
2021-12-07 15:57:28
1
77496272e15fe8ed37752ff60b4b49f0f8cc9575ece371a845f4b97eea71c44e
67
2021-12-07 15:19:57
1
4efd4997a94d4b68ee9b625aa2e5c08f98284a4ffa918b58dee03219160dc396
65
2021-12-07 15:13:53
1
237074479a79bbe33f5b04b5133d6297073a860f36193eae3e5bbdfb263e0acc
66
2021-12-07 15:10:07
2
8ca449f8adc6f9e063adfe1eca154baa46d2c49c4ff3a21549429b044c33ff0b
66
2021-12-07 15:01:41
3
267ba268d403788f42944523ed2bd69fd019a35279c0da6981643de59d260103
65
2021-12-07 14:58:30
1
aeec92da722f46dad44fa459c27d7cdf0454c26d17467f9306686a0639fcfbcf
67
2021-12-07 14:35:02
1
4305bc6b6e780d48b0f0553598679479cf77668dade2bcd422d3e913da85d74f
65
2021-12-07 12:19:08
1
df96cb83a911c727a3873eae719c2bfcf17fb6f1c7136a0ddd370035913f4fb6
65
2021-12-07 11:53:19
2
ee492c42398616b76f7c4bbbecfd14fd79b2974f2cb62bb38b5d56cdf9fa2bd2
67
2021-12-07 11:40:37
12
ecd8c9967b0127a12d6db61964a82970ee5d38f82618d5db4d8eddbb3b5726b7
67
2021-12-03 13:23:59

Rule Matches per Month (last 24 months)