SUSP_VBA_User32_Import_Indicators_Oct20_1

Rule Info

Date
2020-10-06
Av Ratio
2.1
Rule Hash
a340cbb5bcacf19bd963da6aa68fd662
Score
70
Description
Detects indicators found in obfuscated VBA scripts
Name
SUSP_VBA_User32_Import_Indicators_Oct20_1
Required Modules
[]
Tags
['SCRIPT', 'T1027', 'SUSP', 'T1136', 'OBFUS']
Author
Florian Roth
Minimum Yara
1.7

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
4
Clean (0 engines)
24

Rule Matches

Hash
Total
Timestamp
Positives
VT
a709e591fc1c5320deab4f23eedaca6dee493961ae427de40e5af6568f3a5f98
59
2020-10-21 03:07:53
0
ef1b9c219d57e905f819f32a5c7d8dcd389ef6317afbdf40b349135a7c370204
50
2020-10-21 03:06:23
0
5177c0837c78ddd5fa8778981579c13f9fbe583fa7cf0b8c59c4b7b2a7b77954
60
2020-10-21 03:04:53
0
095fc9f40bd4677b631900006f2485b71b57ce529985c410a138361880fb995d
53
2020-10-20 15:36:52
3
a6b8ceb9908afb97470d28ca059d8d4f522553a966078ab86f600fbda7b1eec7
57
2020-10-19 11:01:48
0
72631212d98050d33a854f8e48fa630fb48bfcc21feb60e487509f099605c832
57
2020-10-18 17:44:03
1
8b681c8ee325504105bcbf6709d24c45406359cdafd641ef1747077ef120695d
60
2020-10-17 18:17:46
0
e2f0f30d9a9228a82ab3a13231c59fc75811c8ff2d6d5d9b509c1e3dbc21e58e
62
2020-10-17 18:15:44
0
7868a1740aa9a0315cc2087fe2c313580139339366f1b83a2b9571df9f8572fe
60
2020-10-16 00:04:53
0
d43705252d24d42fdf94973bf50713b68dd859a1ac48751329ca6d8fc8176fb7
61
2020-10-15 18:33:50
0
a2f46a257ccdfea68190edbcbcc4fa9ee53ce90e8a3602a58aec0177b7a9a82d
60
2020-10-15 18:33:29
8
ae8992bcfb9751bf954ef58ead7e5e2d0b42cb6e266af753da0e20ff01393786
59
2020-10-15 14:38:34
0
b03c7d1f7aecfbeeb1348c167fea321218bcd23814b8d47d6cd74ef0e965d280
60
2020-10-14 11:22:50
0
38c22563a18fd86a30be6027fa3a8636206ee64f01571f9c6f8406b695703413
59
2020-10-13 20:39:41
0
8705d5847d31602b042267d133cd225ceaf68229c68201cf9a6ef4ccdd58c37f
55
2020-10-13 13:13:28
0
c479fc0b11c7404837b0523761dea159d59b9a14c5546d8e445e3cf5f961cbad
59
2020-10-11 02:04:50
0
c7127b83a6e01b2817167b541eab0058ab940292ac6483554d46f4cdd80988dd
59
2020-10-10 14:19:37
0
a5e55f75b0a9b1026e2c75cba8fb75864056e7ea357a6030e325fc170f1bb7d5
52
2020-10-08 19:21:59
0
78c4aa304715a745d261145947be498399774913123caa0eab85391edac65d35
59
2020-10-08 19:19:50
6
dbbd3703134f159e76e9466e56328ef606ef5319de559699956ad43764c1d706
59
2020-10-08 17:45:21
0
f501d0250c1d3635664ce498c4fb35472fc96756ceabd9783a703dd361eb5daa
58
2020-10-08 15:45:50
0
88dbd0491638981c93c99aef16eee6aec8f56b2ac0291a3a92cf6d8ca525de3a
59
2020-10-08 15:27:59
0
86952bdc2094bbcd7d3d0fe4d9e10645dbf1447bd731df7c5993f6c546310033
59
2020-10-08 02:13:29
0
a0efec53bc96ca053608273cb03adff5dba92cfcf1a7880d8e9a043de8b30978
59
2020-10-07 18:04:18
0
2fd3d4eafc05c1e787889f27792761ae3ea688f60bc5d74988ede6d112adf0f0
59
2020-10-06 17:00:20
0
a8bd70d4ebe5a6ec32014fc3b2a0303d60128911870121a1867b7e785ef2c102
58
2020-10-06 15:15:22
0
15c76fc3bdc52a6505ee27649eda0e959d30d5910fe401fa403acfa789789c85
59
2020-10-06 14:22:45
0
bfe900e2237f6c7cc95758f581c2cc19f784ddf8e90cad5ae423fda2e7d51ecb
60
2020-10-06 14:11:07
18
8154dd7eb73e77a20913ae3083029d89434280550b37ba351a9c7a9023dda23c
59
2020-10-06 14:11:07
0

Rule Matches per Month (last 24 months)