WEBSHELL_ASPX_Exchange_Encoded_Mailbox_Attachment_Aug21

Rule Info

Av Ratio
0.0
Required Modules
[]
Name
WEBSHELL_ASPX_Exchange_Encoded_Mailbox_Attachment_Aug21
Score
75
Date
2021-08-09
Minimum Yara
1.7
Author
Max Altgelt
Modified
2021-08-13
Description
Detects an attachment in Exchange that is an encoded ASPX webshell which might be decoded by saving it as PST
Tags
['T1223', 'T1086', 'T1100', 'WEBSHELL']
Rule Hash
4898f32e4f973938f3d336f83dd5aa85

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
0
Suspicious (< 10 engines)
0
Clean (0 engines)
29

Rule Matches

Total
Hash
Timestamp
Positives
VT
57
e38a26573f965a25caf0f1e7e1b8497a3a2d8769c6fb662096b6d12873ec6cb0
2021-09-24 15:02:22
0
58
1f5de5bd8e70a96a3fc6af20a5752f2305787a2ecd57e27f3b1e12931a8658c3
2021-09-22 13:26:12
0
58
eb515e89bb2a6553d515a9c79fcb325d0e68723931dd7f97d3de42fd961c9cdd
2021-09-20 20:41:19
0
57
806badaa4f265c7c4552343b40a903ff90a1c405b5660b4f144df8d4faeec1d1
2021-09-20 10:06:09
0
58
9441e173f8161fb0a7bd9219fc4709d87885ec3a56fc223f5d0b46077245c2b0
2021-09-16 21:22:57
0
58
e03f6859fd9ad56645cae2cf03a57f9ca2b7f8e8ab96d1c684d8edc7d277edd4
2021-09-15 16:35:21
0
57
b8f31c21f12e9c7b33a7a8bb78f5a67afc77a2289c08314275a3588215c663c4
2021-09-15 12:26:50
0
57
2c3c8e5b7a6169285c37e9a1f3b4896276267a0f49de2b402c50d693f66d36b3
2021-09-14 21:21:28
0
57
870508e7edfd117aa4ad90a94acf21ada4a84797c4de07b35768f021a4f0f074
2021-09-14 15:22:08
0
58
fe1a967883be0d6537d6b586581bbbea2636c70bf2eb1722c772104089fecea9
2021-09-14 12:07:10
0
58
970fe47c6334d912f0b86cc26c88af93b61ca364712a9eaeb4894696f481306e
2021-09-14 12:05:14
0
58
5efb5e3fd4f74bbefe1ec7a38d73957dc0a83789a1e909e381e4a83451939dfa
2021-09-14 10:16:47
0
58
4a34fea29c2763d5a9a28d1b17daddf110d21675c88f0e5aa577222fb9d840a4
2021-09-11 15:01:19
0
58
33b89a0857c892564f03d59e8202b8a165c03f73eeb69166c128574d39f16c00
2021-09-08 19:38:16
0
57
29976057e455814dd11a96ed9a9af974e7ca2752412ca325b3f89bcd004f57b1
2021-09-03 12:06:02
0
57
08eb9ee68bb98582095fd5b1bebbac678f1eab124d106cade27db095979bd587
2021-09-03 11:36:15
0
56
77be776f3b2fba38539987866795488115693daef21c78ea8dc315bdad7d463d
2021-09-03 07:02:12
0
58
6c8699ae2028c2d019994523f0d75861f9530256da8f04556f0862b13c26b401
2021-09-02 15:05:13
0
57
207a67ae60aaa615bc1d774ced6b44850d287cac4d8aa1e6ea99ec705f80c130
2021-08-31 21:33:38
0
57
9155aa6f728d0e4513b52d81c0f1ecd891e5799b3291ac21c920c37b5815ff17
2021-08-31 21:07:23
0
58
36bd9b4396a3cc5bd6992533b6289229fad0a5919c565432a8f2b26981b91e23
2021-08-31 11:18:24
0
58
50807217147491af55229836f153f132c5062dc442765c25378069dd6ccb4ef3
2021-08-31 10:35:26
0
58
37f49c49f4b0eb8d8304f1ee2d9c94d2a71fe1d2fb1a5fd786d130c34377f30b
2021-08-31 08:16:52
0
58
97b84e02d361d174ab44192ec4100469a9e6183c2ccef6e585c5063df463db9c
2021-08-30 15:36:33
0
57
889a032740c1f19d22e4972db78cd5d9325f4400bf5428a67a6aef181c805615
2021-08-30 12:11:53
0
57
a39c16eb5035f14a22b5eda8f7f245f256657951c354ddc3a928e830b25fae76
2021-08-30 06:56:45
0
57
480900a8b7dbd34973302842b470afc09446057b165bb6e6fd7eec20528746c0
2021-08-26 19:31:48
0
39
bc26218ac35f1590b4c8dc845d5e936d58b1732e43f0e7448e3bf7e0a31cb8b9
2021-08-18 20:07:32
0
52
9d62a16a38e3849f74dd842f379fd9c92c1f8e2f6c798887b4de88063801dfb2
2021-08-16 16:01:39
0

Rule Matches per Month (last 24 months)