WEBSHELL_IceScorpion_Jul22_1

Rule Info

Name
WEBSHELL_IceScorpion_Jul22_1
Description
Detects patterns found in IceScorpion webshells
Date
2022-07-11
Score
75
Tags
['WEBSHELL', 'T1100']
Minimum Yara
1.7
Author
Florian Roth
Av Ratio
17.35
Rule Hash
a5ec9563d5ea5c18a3fc9e3933c3336b
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
18
Suspicious (< 10 engines)
20
Clean (0 engines)
0

Rule Matches

Hash
Total
Timestamp
Positives
VT
28c4277df19c8da032704630e738136da540426ad9f3caa0be7b131237b0539a
60
2022-08-19 09:08:56
14
1096370d6aa7ece4e6509c784fb39f50df24aae964e8abf0d7b84c67866d0ca3
60
2022-08-16 04:40:30
15
2e853eeaae4fa2f8026ebd3beae1f05e9e2532925135f8e93eb66c993b8a9788
60
2022-08-15 11:27:48
9
d86fae9f371108a6ef74753ad16a2337998cdb60046c95a1b5c25dbba0365df0
60
2022-08-13 18:02:02
16
f57316214ffcceb5031e23403c2946d6a6387fc9609662b1cd43c0b270d4fb2b
60
2022-08-09 05:56:10
15
17f36deaee5c5a5a23aa438796502a3fbc9cfac8c23c5152faa2be5c009166aa
60
2022-08-06 11:13:15
15
b87acb6cc1b36b8f3fd6086bcebf5a8a5034026d3067d681531fda9fb55769a4
60
2022-08-05 22:42:52
15
ae2f270ec6e9b7d35dfe678309d8828f6353358ac6adc8957742691920c9e01a
60
2022-08-05 17:52:10
15
47a5da831ca293e1c074ea00a239d58e12ed2e8a080aa2d50a0e3f4f7a36461f
60
2022-08-05 06:21:53
3
a57f7a812c03592f78659ad94dc8d0496a86824eef4cecf5a6c0c6f046531509
60
2022-08-04 09:42:41
6
9f4d3d2b3abbc07c892274872b0454315105b8e743cd6051a37b3b613c4b70a6
59
2022-08-04 04:30:47
5
80403789bc8c23e9fade40d0894c5e654c57929ee37c0a0559d82cba6d68e9e7
60
2022-08-01 20:54:06
14
2f866d369a5275ccf1e536b21c3747b800b1c53d8cd9175bc1fdb40d3d584eff
70
2022-07-30 15:23:39
4
54b2e4bdfdfd99d5e1407573cbefea8ad96cc5477ff1ab1d76c3de9adfd392e2
70
2022-07-30 07:42:41
4
3cf81eba189cdedde93a9f4fbbb85bed58dbfade1bc7a81656c205957a7de677
60
2022-07-29 15:53:54
31
ac61df03c0ebaf2c6366e923dac0a04bb347a9adb1e736c46ada7a2dc0f07eab
59
2022-07-27 23:26:43
8
019cbbee61917f7a0d7d62f6a546b5c4d1a5482084dc83c5958ca106be8816d2
60
2022-07-27 17:10:50
15
49b255874522a0b0d7a62e11832f6b94b4eb8a7d70b3b1ec23581270c031a8b4
67
2022-07-27 12:39:07
2
8b27e19e3f3954768fe967eed79c9ce47b0d49fc8a21b92cb85d9b65cb95fa88
59
2022-07-26 12:44:55
1
ba50f3acc6ab7b5574d0d042a8464605017a6c86757149ee5802365ce16da295
60
2022-07-26 06:31:07
14
f353eb7325eb21e1f62b7fa60f90607559adc33f7eef3e0e913cefff07f81b6c
59
2022-07-26 00:11:51
8
0cdf5ad3a69a9bf4b33d07f19158b22be2a57b480a2a848c1c76600c033be7ec
61
2022-07-23 05:46:54
28
f9beb37acb2beaa6ec95380e17d564525f3109d8f1b06a64ac5f87d88b3ced72
61
2022-07-23 02:31:15
30
fee4c3882673e9f0bae3ee25892a29c3c97934b5a7dfc09d6b1e6ea11473b133
56
2022-07-21 19:42:33
7
ecc918aaf82d88841c57ee7b0c0016b9af12b2ea067a391f9d624f2d29253d91
58
2022-07-19 19:43:22
8
fbcbebb947cf58b73d07a363a75c583f65dc75a1a9d62bcc6320f05cdc1c6adc
59
2022-07-19 15:34:55
2
19226818a5f7c4b5403869bf248e608f4f167ff977ff3562ce9d31d4b0d7371a
59
2022-07-19 15:29:24
3
892919aa92dcb6c9290f8131c4a82e00627a298e557a20c5f1f44a4d1420b403
59
2022-07-19 15:19:07
5
465a237eafe90b7f7fc233b5b3e01f83acc10739ac7333df678502f1e8f9eb90
59
2022-07-19 04:41:43
2
fbcd17470a2bc2ca0a6d3b26028048a9ea0f770d5b93d28df209117dff4171fb
59
2022-07-19 04:37:31
2
4f93125658064c9029d68fc744e720165113dcca5bd8e362233f2966acddbbd0
59
2022-07-19 04:36:29
2
a9e9670e46ade8341092dc7f0c30263197880f72c9e1d323878680c954ef6612
59
2022-07-19 04:27:49
7
c075dc6745111c3265267179a3eb25e8c94fe61c05f03dc79eaf8fb0a9ccf262
59
2022-07-19 04:23:31
10
87c2db897362606bc48f8446437bf87b4c6743fe25f3b5b3b0632d5f0b88b964
59
2022-07-19 04:20:17
11
3f427430fe5f4cbf39606dd0b4916ee50da89346c0143c13673dba69653e8a94
59
2022-07-16 18:57:46
14
a245f42d562d366770e165eed42e0d60c739a4971eca70766ba65e5eb9f96e35
59
2022-07-14 13:35:26
12
6e5b8be2f3a6ab270f6c0309d96e8520162a0505ce23e2a3a328b201c1b35bd5
58
2022-07-13 14:07:00
7
a20fd2cbc3395b2979adecdfeb92c8ab99c108758a3be8c3c630562e67e80ec2
59
2022-07-12 17:50:34
16

Rule Matches per Month (last 24 months)