SUSP_VBA_Lib_Kernel32_Import_Oct20

Rule Info

Date
2020-10-13
Av Ratio
10.45
Rule Hash
28d966919a56a19968e1aae23c6e6286
Score
50
Description
Detects VBAProject files which import kernel32 functions
Name
SUSP_VBA_Lib_Kernel32_Import_Oct20
Required Modules
[]
Tags
['SCRIPT', 'FILE', 'SUSP', 'T1136']
Author
Florian Roth
Minimum Yara
1.7

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
7
Suspicious (< 10 engines)
15
Clean (0 engines)
29

Rule Matches

Hash
Total
Timestamp
Positives
VT
53374d673d89a19b655db18ea1ff650334882dc6f2739be8f15105df218da6e0
51
2020-10-20 22:25:58
30
967676f9ad0204c2f7fd3c6a734d1c6424da1db45149f90689929e6394018e52
55
2020-10-20 20:39:31
36
0139d2313cd36d69342c8c06261dbb5b65f775fbf9af32868dce5f689119e0e6
59
2020-10-20 19:07:12
0
3e08829944c57bfc4964f304ec41618ea2218a28700526bc0b8ab79bb2b18f2c
59
2020-10-20 16:05:38
0
2bde41a0e45ae8719531de4289861790bc7501f92b9417aa1cfac1b730b8f642
53
2020-10-20 15:36:51
6
11104322a3309b7d5f3f79b8b0f122cd86baf51779739003f8e047ff63997fb4
61
2020-10-20 10:04:41
6
85b9e2f126e417ddb11db83a2be05409a3138b9b782d0001fff6a973c8ec4a81
62
2020-10-20 00:20:57
0
215d1b2f3268a8bc1d07fd5d0267d3e1bfa729b84edd27676b67647c264a9bfc
61
2020-10-19 12:32:06
0
d023de03f59d60b29cd36ae085765e5862aef6b2a9e74e16eefe08146fd28032
61
2020-10-18 19:52:01
0
a57f7c4f0745dba0d31b84df9a0087c9f73ad741cad2133a15b16e6c12e9cc83
61
2020-10-18 17:45:23
39
e10bc87038c3fa0fb0600200fbe547da0f8660d77f8caab4f248d9435e0f80c8
60
2020-10-18 16:42:20
38
e6b458823ae5dd935a7ed0a2b15f4874afea9cf63582652ec79c9676d43e5f54
62
2020-10-18 15:49:41
1
33b25bcd2c3a3b606cc3102a90d6f3ed6ebe1795d51f958168322265cf731904
62
2020-10-18 02:40:01
0
1b216bb412bb8c4199bc2a199bf3ceacec52844eb50ce6fe5c26aa43b0d9d8dc
63
2020-10-17 18:16:18
1
832a5086c6a4114884221e34f8c1cf40be768ae80fd5090008ba2e53defc6ccd
61
2020-10-17 14:34:46
42
5d915baa4a56ddea8f231c4d8d54f13ba780f75f91f81813638f6d9d5579ec0b
62
2020-10-17 03:33:30
0
6abbb76255e59e984378557dbf2f1ab124ee1cf79a3c7374eed03c171cbc0b1a
60
2020-10-16 18:37:56
0
7ac3c31e5aac746b4c46ca59b7dd643c2803c79c328827fbca1693b195770057
60
2020-10-16 18:37:25
0
261a85522f41455b52596193e95b4d70b0298bceec8817f21856327327b3212c
61
2020-10-16 18:37:20
0
31623300ed4b8d247c5fa4436af97a72be1f9a8503535e8c37557902dca1f04d
62
2020-10-16 18:36:56
0
0cee49cf634d3597cd2024b05334607802bd597becfdb074370554e3c6771f09
62
2020-10-16 18:36:01
0
f2a4a9e5c57846839891fa411fd19dbb56ca7eb9e4cc05c028d2ec3ce4edfd82
60
2020-10-16 15:54:28
0
37bc4b6af1568121de01bbaa326ac05821a7eaceb6877cab45d5e549e5c1b404
62
2020-10-16 14:35:37
6
4a4efd92ac9d814d73b171f158d5d462878274abe59fa080bb117c5e023097b5
60
2020-10-16 10:46:00
0
3729931f7d6b8520d0fded839d8e3ac3bebebfc61a3d3b5ec23c6ff130af0b1c
62
2020-10-16 10:45:32
0
143805ff9a895f1ce0765ed137e4fe6a91f1f114cca68e7cedf2d40573ed81c3
61
2020-10-16 10:43:02
0
b0ade1596e98cfe82bdadafe5d12c3c2d0a903de913ac35f401ec05ae4ebc29b
62
2020-10-15 21:31:26
0
99d5fc0240c407d8daa94ca9538d395367ae6f998a083329f2f5e805317ed4be
62
2020-10-15 20:11:02
0
9f636fb0cb395e3aca78774266a0423218daceb89da2155664899c4c6c487e47
62
2020-10-15 18:50:57
0
f93f54bb7280a771f4a95fd80d767f301ad01a6ec2df4249d4da3bae7a2be80f
62
2020-10-15 18:35:00
0
ba144814e193ec0f9c22782ebff6b6929923ca87f3c3b6b4c32efb7afe9e718b
61
2020-10-15 18:34:26
1
537ea5fdde51a6d503f2aea5465d8290085bd4111d7af9b5827f031a0fc0367b
62
2020-10-15 18:32:44
1
e03a3ada7c4bbf778626213f058166af4c4deb5e782ecf2cab3758bc5dc5315b
61
2020-10-15 18:32:43
1
93b3467b745d0ae3177021dfeda74b8b4ae43f474c072d876a3e4e97a55ddecd
60
2020-10-15 18:32:11
3
f5a373b1838ff398969f72c65425b22ef68c2e6b95a481ff84c20e27774718e4
62
2020-10-15 18:31:54
0
04e632c1e065ef9cf365d780d4eedb46861688d72cd1934f24ea903daa5b0e48
62
2020-10-15 14:40:53
3
33e4170faa527f293a96bee0241b565510f85e194447bc017cbce73ee0d35b10
53
2020-10-15 14:36:51
35
c2022ea99cef1e91cc2cc5229aebd7eb3092ebf226666694842f99c93214a6d0
59
2020-10-15 14:36:51
42
5b1ae7533c3f4f77403c30da3b2e7d1019a287356b7b880638fc8386796addb4
62
2020-10-15 13:25:15
4
cdbeb5c91bd9bb5b3a63c2c5150bbbaa4ed5dc0a40f4ff474ae5bfbf01f47205
59
2020-10-14 23:32:45
5
9bf0dd5f61258103b7495c7ea3354a91edf299a5871b7f68ac244673bf3cc34f
61
2020-10-14 22:47:21
0
5ec6be5f4cba4cff39662f12d29fb14f1339c145c939b68a9d8247b270dbdf97
60
2020-10-14 22:35:21
0
7cf13431363085d163f6e6e033ad4a74adfc6c1fa8c5fa3e6f4aa09cf500e53e
62
2020-10-14 22:32:20
0
72c9b8311efe7867cc8468d3d5c5c6159d6679b9a7264b2717fc46712f530374
62
2020-10-14 22:31:52
0
4cf52aadb9f0e2230970015e3764e6330f34ee659b3d143a8382158d4b27b00e
62
2020-10-14 22:31:24
0
08ad57b6c34fa2a650c493b774efeefc8755960f2555046728d9f78a71dd5a7e
61
2020-10-14 22:29:27
0
5b78adfcdeab19f87e40e5cef81dbf13500df924d3df0599ca8ec3d690f40cd6
61
2020-10-14 19:36:22
5
92e29ee9e7b37bbc0a9e16c7f669a042062da05423e0129a0dcd2daffa576dae
60
2020-10-14 19:06:33
1
4d1a2e83c892bb2e3242340f77b92187af67f0eb3a323d5a2d70ec4ad8eb557e
61
2020-10-14 16:39:49
0
37db47978de8981fdb4723032b02025022787b5524515754f302e2b48302004e
60
2020-10-14 14:26:13
0
c8becd1379194f9af574ac97834695d2b80fc260bfcd27654a79416f9660dc17
61
2020-10-14 13:20:21
1

Rule Matches per Month (last 24 months)