SUSP_base64_Salted_Aug21

Rule Info

Required Modules
[]
Date
2021-08-12
Rule Hash
a778a1520193856d8f07d5637a011073
Name
SUSP_base64_Salted_Aug21
Author
Tobias Michalski
Tags
['EXE', 'MAL', 'FILE', 'SUSP', 'T1132']
Minimum Yara
1.7
Score
40
Av Ratio
20.53
Description
base64 encoded Salted__ which is used as a header by openssl when encrypting with aes

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
19
Suspicious (< 10 engines)
3
Clean (0 engines)
28

Rule Matches

Timestamp
Total
Positives
Hash
VT
2021-10-20 15:14:06
68
45
05e6b093d34a684647b35b502babe7e5ff1a087ceea1c4a964be662a3a0afc94
2021-10-18 17:04:01
65
0
de34b447b0ccb91373d78a1e8f0d857ba1ee40d097edfafaf889c7bc8ca02523
2021-10-16 10:29:13
65
41
0176086aa33ef67a115c32d21c941055e8a9aa15972e6bf88b9ea7db57353abd
2021-10-16 10:29:11
67
38
3dfb9bee5caf96a716ab9ca560db670e28591f76ac71f7bf87a78b18a50bc662
2021-10-16 10:29:11
67
34
9933f40bc304b335b3393959301ba341c165cb13069d88e477510af06d776ea7
2021-10-16 10:29:10
66
39
66c9506daddc82e7a5844ff570cc5d5dd864adc90d36b16d15d4af97c76c5eec
2021-10-16 10:29:09
67
42
cadbabb4b9f36f69c2f963c4c87295f186672e01c24723d72e58ecf6781303f4
2021-10-16 10:29:08
67
49
8e2a8d4ef83c8d6dd3682c6292784aea76aa19b0742169aeb88110d31e12ed42
2021-10-16 10:29:04
66
41
c17651e6953c0a83abb95bd5226fc2ccff4a3cb68499412b2f61d15a5c0a6579
2021-10-16 10:29:04
66
47
1be4b9b6d04fe3fae796ae50d15d5cacd181f6487473ecc6521e3d33213149b1
2021-10-10 12:46:56
67
31
fd765103cd948bd0099cc05782348f2b425441a87a7f38f1bfcdb185aecca84d
2021-10-06 12:00:42
64
0
890e098ec49a9e752cffaec11024472a6bd37fc8e1c2978dd6acb636ae0d5839
2021-10-06 11:58:20
66
0
98f48c5900ab0b0ec2fea973a9ae808417503df553313cb45b20eb9f4541fd13
2021-10-06 11:58:19
66
0
5f94e5abcff81ae03f76f01cdf1f60bb244781d3894a7afa13c27a803d9a6753
2021-10-06 11:56:01
66
0
92e0d1d0b716fa043a80b8ef5eaba4b984497abc5e9174456f60f6c70d12e98a
2021-10-06 11:55:53
66
0
f348aca35f94060ed175f758a11e8bf8958b79f205e43baa238b1f75704736cb
2021-10-06 11:53:34
66
0
c752a9e46d86f51f9256dff417cd2a40d775d9f79dd28272fd6d971d5b2ec0d7
2021-10-05 22:32:07
65
4
824cd40cea1e2c7956afc049ed58a2e669b18e9e20af0866f26f43dd5f2dcfd5
2021-10-05 19:11:55
67
0
d4cdf55c091c74b061c7b33cee576f99a84afdb5430a3cc2de5e7e475adaca2f
2021-10-05 19:07:15
66
0
57f38a59cd2ac8bcf2ba123e4b73d15ecf4152c44942253e18b355c183b599da
2021-10-05 18:59:25
66
0
be7c957245f238a089aca5fc4c271a301b2b0b58d48eea9a0d8f28d485c0bdde
2021-10-05 18:58:14
67
0
0530d1ea2301efe52729bfcc3239236e903770d7b124e64ec511a3fbad16ff3c
2021-10-05 18:57:08
67
0
81c283e1877d3ac639759f6ea5fa3c11ba823c1edd1193b7b3b3e8ff6d78b5bf
2021-10-05 18:57:08
67
0
eaba5082159666c5ba4ba983ee20cfd50debbe69c6f028c7671260dc96100985
2021-10-05 18:57:07
66
0
1ecb7f5fddc066125d14e218806458e511dbf4e7532b4b47dd652007a0ccb20e
2021-10-05 18:57:05
67
0
c1a94a62ad743591578463fb6fcf04ada84f84081d6292d9a40973400c5de7ae
2021-10-05 18:57:05
66
0
78a4796e531ff12651d41a97ff7ce901b32e2c4e360e0de925dfa687de800989
2021-10-05 18:57:04
66
0
1ef61b9767eacd893622aad70213a82c94cf43497ffb8804e6f3cab24ff6ef81
2021-10-05 18:55:53
66
0
2ebc3eded5b035d2b3bce541782e76675c4c1fb259050c1b24ea47df3ed6dfad
2021-10-05 18:54:49
67
0
c46cece480495e198888a8bf03bba9f90d397903aa64d11e43c0c630572ed601
2021-10-05 18:54:49
65
0
71f37fb178787d3dd494067622ba74089327020fd99f0432ed9da6579aaa9166
2021-10-05 18:54:47
66
0
6b5e93808136797f01ee0aff290e6bcd03799e817336851512c13403cf0ea056
2021-10-05 18:53:40
67
0
1e6529a3880a28926f26a416406faad8493b3b20f208b81533da62956e16b90d
2021-10-05 18:53:39
67
0
fe6637cce384ba0a790472896821f5a09e7221383c64fcfef410f1a5db8b5717
2021-10-05 18:52:37
67
0
8463c2a8c4140f48bb6f522c4f51f4ed3868c1d16b8d8f421f5b2ea1026ffaf9
2021-10-05 18:52:37
67
0
e59a77ffe69db08aac0c06f6b72d60d96785fe899751801b733550db4709f4f2
2021-10-05 18:50:15
67
1
2168cdf1f42054fb8715d5c2ebb7c4251a4ce796c25289d04e35421489c49eb9
2021-10-05 11:30:26
67
45
df2e79ef427a4c4b0ecc0cdb7d614852790e941378c70fe055909739ca77e1bd
2021-10-01 14:54:40
67
48
db798962940ecdebf99835133cfa43b3b563b088b69d86c1dd5e2bdd738e2bc4
2021-09-30 14:35:32
66
19
c24e5ddb4bafca38510ffeb882eb7117f8c24b7801292022e1908d4c85579723
2021-09-29 12:23:16
67
0
fa4a63b43a5918b1dab77f3bd4d3991828584c0406783bb7dac7a3e483566195
2021-09-29 12:22:06
67
0
e5a4ee2dc54f619a2bbf23c4f836d7890c22e7da07611639cdbaaa285e4da6e2
2021-09-29 12:20:47
67
0
89a754208b672dd8f3cf95e2aa9e57b5d7b06ff00247812979c319780cf5abd3
2021-09-28 14:39:07
65
23
71a3fcb76053f961bf8c198ff6da6579ae05dce102623ae8341846998656f536
2021-09-28 14:29:46
66
27
63277a794f850e9e3bda693a98d18726fab5a07c00ffcc83804940ff4a26cf62
2021-09-28 14:28:37
67
28
bca2215ae05cae5ebdf631746ec4d10bfe992e8ad25affaa550f7d3ea9c215f1
2021-09-28 14:23:46
66
28
076d80f4a6203c1a1cc04e84d548948d6bfda287a44b9ecee5f07364e7ac43fd
2021-09-28 10:37:20
65
1
37bd34f2d7652a7f67744b69fb26b0903c6970a1f38d543a2c6d1753a31a0d23
2021-09-23 11:59:58
66
26
1a68f18c5e8574dc04aa49ccdc8d121cae342ba5bb4724cf1043758044da47d8
2021-09-22 19:53:16
67
26
334030ddbc511bbf54c6e443b5e27613fa964c94db65ce702e83c7b6ea3b58de

Rule Matches per Month (last 24 months)