SUSP_VBS_Jul21_1

Rule Info

Score
65
Reference
Internal Research
Name
SUSP_VBS_Jul21_1
Description
Detects suspicious VBS indicator combination
Av Ratio
8.24
Author
Florian Roth
Tags
['T1057', 'SUSP', 'T1047', 'SCRIPT']
Rule Hash
dfe3311470e3ee614fb70663e0c97c37
Minimum Yara
1.7
Date
2021-07-12
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
8
Suspicious (< 10 engines)
39
Clean (0 engines)
11

Rule Matches

Positives
Hash
Total
Timestamp
VT
1
e57dc4414acdc828b1e23852ae58d467fb1d3301b737b575a884335046b364c1
56
2022-01-23 10:44:25
0
75469c66ac4a408e76bc153efcb58af015df1188ea976e6c8bc75ea507a950db
54
2022-01-22 06:49:29
0
ade041f5f3efaffe174b992c6f92fb684c70b43df2e309972f140d326055da75
57
2022-01-13 19:24:09
11
5391ffe189c6cd1b782bd1d2abc4bfba675ee20f72cad9cbdf48c7733a96763a
57
2022-01-06 17:40:55
1
be74b5d5738d6ffdaef3823ee56f13faef435348c24605fd66abfa5e8f34d3c0
56
2021-12-31 19:15:26
0
512fb2e2dd97f97804f82980f61115147102d246e42853968882c30cc3f4d5b3
56
2021-12-30 21:31:39
2
1d3fd0060550c7d4410e16d1c6188f0f96aaab0f5ca2a3f1775793f9158de16c
55
2021-12-30 04:12:43
32
6780302fa462151326e254fc9212ae7582ced3f289b06d1f06e4d7fe9ebdea96
68
2021-12-22 00:50:16
1
0f0cbc098884152009a322a661d3f77f379e5812bc16f0536ffc6d0e1a87babc
56
2021-12-12 20:18:37
8
288171a1f736c91c807b0be2e104e42029a9eec3b30290d2c21da825d33aaa1c
65
2021-11-30 19:33:18
1
80f73c72fb07be2c76eb7076fddf453276b828cf3f9d3a16e50eded35c2897d3
54
2021-11-29 14:50:06
1
09fc2df680e29da8e3cc50849c4fdc2e1d84f6dd2830d259605b5a20c4fe67c0
53
2021-11-29 14:46:24
0
063d78b0990829c994925739d5e269a5994ba7a22d450adec31ef28006971cb5
56
2021-11-29 14:40:16
0
8306e56be9117a8a917917bedaceccfbe6a8ed512b50213d6c7a97754e3aa241
54
2021-11-29 14:37:32
1
40b923b12589a2935532885081b7816db51bf1bb1ad4777f9820bea865f0bdee
56
2021-11-29 14:34:49
1
dfd63f95b35f267b67c6fa2c9a7eb2ceb17ec1656d32d725d989179e288bfd73
55
2021-11-29 14:33:36
1
c960878f8a9af88ca99a79ea6272a73cf6ef062eba8dc620243ef0e5f8d7ac5d
56
2021-11-29 14:32:05
1
f4131ac419d3dd13c6b5ee554ddcf61ac720aea9fdb49f0b2fec6c7c183e1f43
56
2021-11-29 14:29:35
1
6ac1e5dfcadb9b89e94a87544ef2e3dce9e8fe99bc22d3019d4f49df0d471d0c
56
2021-11-29 14:28:22
1
c0b55b29d23fbcc31cff098018e968674cc3c74e9dec5cd085814453ee3ca82c
53
2021-11-29 14:28:14
1
90b0897de57c79d5f91e9b57bc42272d63aa8019fe18a704a3f034180e85fb72
56
2021-11-29 14:28:07
1
53cfea586852735cd88e68c97b88e50f179c92baa0741aa28bee27b02cfffe4a
56
2021-11-29 14:26:57
1
6865941d58cdb31cb8591cfa47c9d6cf0773ce6603cea0ef3d8af9e9102fdcbe
55
2021-11-29 14:26:56
1
11f83abb41e3a5594aa8ba31d1ffae21406718b1f9267aeff67e5751553cf98b
56
2021-11-29 14:26:52
2
e8abcce26ab7941c7cdc0deb92f148b34ce614ad2c58e75d9f859cd2f16e273f
55
2021-11-29 14:25:23
8
2f14632e51ba5610a64e527c130c6aef4518b1563c3562d19ea5a8dbac64b2d0
56
2021-11-29 08:44:24
5
564aa3a47e877913538caf9c4ad6525bf4dac7ab958bc0ec5b2a43e75e2ba9a0
56
2021-11-22 15:05:17
2
213da7aac308b8e152de4c761187ef6c609609355c0723d04d4e2e04d5818739
51
2021-11-21 21:19:27
28
9f4169a9a4a62b466dd131f4648cb99edb190a6dfae2d92b3573fe2ea22b85ba
69
2021-11-05 10:01:01
3
fc83340e054e7365f310d3b9b42cf883562971a437b6b4e10836913eecbc40c4
57
2021-11-01 20:36:54
49
715c96fc17a6015a3e53ccbf35aee42a23009e1c188269cbd39272f45a16a5a7
67
2021-10-23 12:12:53
1
9a7ca2f9278e4f39bae0078c127515d49a2d2087d394445800e1103fc1afb11b
58
2021-10-07 14:17:28
1
020d5c6d3cccd16857e807b450913b8c49a05136094f2bd1c8381fc519239c42
57
2021-10-02 16:14:16
1
abd6072a9e03b244565a293c19b05ec71da3dba8c740d5453e1ab1d023593697
56
2021-10-02 16:14:14
1
c3316aa80b5a0451aa6e1cd31549297c533f5bdea450b5abd01b0c715f2b2abe
57
2021-09-11 20:45:36
1
63d6d3264e4624ce149faa59c5b213dce8ae1b035debc75c4f4765d19bca10a3
57
2021-09-11 20:42:04
0
75908d9bd1c2b00b53315268ac590b2c912c4aebece2f69062fbacf03c1645be
55
2021-09-11 16:57:35
1
efd247e0b3818adc6728acef2e7acb1c65ef4fa838002e1439b1a6478056de5c
57
2021-09-11 16:56:14
0
62888bbd13a6d8b0689b3dbd12d0a2e8f446db8a90c1aee838cf170321dcf4ce
57
2021-09-02 06:02:42
8
2e1561b63f513f885f647fff4ebcfb000c2c02bc20eae6fc117e2441f96f6421
58
2021-08-31 00:27:57
4
2d9a505534f09c2102b9beddc4f5ebe9b2e1a86022dc5bd413327ce417ed6243
57
2021-08-28 19:13:23
1
30b79ab7b4d0b65a4c82fd741a34feabce1d937e56000eee641aee94f6779cc0
58
2021-08-19 17:27:02
4
4d994b864d785abccef829d84f91d949562d0af934114b65056315bf59c1ef58
58
2021-08-17 20:25:25
4
62a984981d14b562939294df9e479ac0d65dfc412d0449114ccb2a0bc93769b0
58
2021-08-17 20:15:34
2
5553ba3dc141cd63878a7f9f0a0e67fb7e887010c0614efd97bbc6c0be9ec2ad
58
2021-08-15 15:25:58
1
bfd4ca71dd09181fd72f2a0dea0aa901dbefdc614839b447c234e273113d7b27
58
2021-08-13 18:20:03
0
31d0d2d4cbedcb4bd71367edf79258b223f39f65a610b6d0f075ae014b0cb747
58
2021-08-10 23:57:11
0
809f17a7509bfe1458fb7bd5cdee07cbc3286b997cdff6eefede26c5780631a8
57
2021-08-09 23:35:41
0
5d31bb870d032826bae039ffaf7761940dbfe65076780d52eb834f2268ce82b0
58
2021-08-09 23:04:16
23
9795849b083fec2932009289c049f8211fcb0c20af54b459a02bfdd6692f354a
70
2021-08-05 01:58:31
1
a0210a696fbe9e56ca30964905f54c2c87d5b6c078c64c93e67a34e6a717d742
57
2021-08-02 12:39:55
2
6b23b51db3aaaa47713d352ed174c8a97436e26df2f77729798f6834546ff85d
58
2021-07-29 13:22:25
22
a3eeb8910129eea5a151896c2a60ce54d9c4d3d1cf7557a1660970cd2d104200
59
2021-07-26 15:29:39
32
cfd2603009dad079db535d33dfc20d9fbb459ec279b07e302cb865a99ad7f641
70
2021-07-24 18:41:39
1
49f710b060fbbaad4a1d317f5789069dd5819d721735e4f1905d25825f96f565
58
2021-07-23 15:09:54
0
ca2847e79b3a8be449026f93c83273674e93f4294505a25eb97a7f23832df484
57
2021-07-23 10:36:55
24
a6b7ce809dc22b6b9cedd4735a02346ca59154a9422b1e47c6d705301968f212
59
2021-07-23 00:39:13
2
381714be29b40feaab40666075cee68c13335cf86aed440c4fc7a247afe02d44
58
2021-07-15 16:24:23

Rule Matches per Month (last 24 months)