WEBSHELL_PHP_Jul22_3

Rule Info

Minimum Yara
1.7
Tags
['T1100', 'WEBSHELL']
Name
WEBSHELL_PHP_Jul22_3
Description
Detects PHP Webshells
Rule Hash
cf44a2d622d0c0139f4178b581ef11fe
Reference
Internal Research
Score
80
Required Modules
[]
Author
Florian Roth
Date
2022-07-21
Av Ratio
0.65

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
4
Clean (0 engines)
51

Rule Matches

Timestamp
Positives
Total
Hash
VT
2022-09-28 02:48:08
15
61
f8c2cf60990138de741e51b51c916e6442276ed5310bf8b5e2c81f5b094222e2
2022-09-27 10:32:21
3
60
70e3ad4e6b935a67e310b35efdda9b07952d824361f276b72a3665e5a998d765
2022-09-14 14:49:22
1
58
ed94f680aab258242cd28ba11694ee136aa8bdcdc6547828bb765ac1793fc9a7
2022-09-12 17:13:35
0
59
6cdbf6a7924313eb045492c0137faed968337e0064e7fa75e5d14fc9f1868702
2022-09-12 17:13:34
0
58
8c33ef54ecfd7b497d1058c2d25ca9b201d78fd4bd79a75caa83088664fd3c83
2022-09-12 17:13:32
0
59
178ed287cff1a626a1ebd8875095fe53dfe46acbc18c5a0822d2de1e9b4b0af5
2022-09-12 17:13:32
0
59
9c8c6fb351f56007cdf325870a3d1037f285d025f1ff5d72e75d6cca512a8328
2022-09-12 17:13:32
0
56
76f4a415103a5072f1bdab78a107c07d06cf53e96f36f026e8ece095a4b94346
2022-09-12 17:13:30
0
59
8bf0a405fac7756c18184e0973023088e7dd7a71c44124996cb6512af3545f67
2022-09-12 17:13:29
0
58
226621954e5666fc2eed5ac4227e3d32fd521165e08d79d697c8c6ce2f15e5c9
2022-09-12 17:13:23
0
59
7d1d3402d7f6cd4fa36279080e8990fe799b13e2a9140b4e127d1e0f32edc34f
2022-09-12 16:59:20
0
59
23a78d8c198bae3f470291f3a67ef36fb186c60fea1d1fc5f6319b848d74545c
2022-09-12 16:59:20
0
59
ef102e2e8c9b03bbdd683a0dde2008c968b2577b3fe13b1e3cbb7bd0985a6b7c
2022-09-12 16:59:17
0
57
55fd0744514467df1fc93d5b8d341024bedb19b3be75991fc146d59aff40f7b0
2022-09-04 20:11:55
0
59
ab36ec693350a3ddaf03a54bc9b0ab4e8b0cd0597c68ad5c28e45dfc016a99e8
2022-09-04 20:11:54
0
59
fe614e23cc775ececb04aa0b0e283ee4a3b22fb4bed2cc712dc86552d7efbb0a
2022-09-04 20:11:54
0
59
71b5f792607ec2321b6f48420512b9aa55e795bbc89e02faaabea6781185cea5
2022-09-04 20:11:52
0
58
3ce30d7d34e602a82ee16e7358cf4b584759c387a31a870a3ab355c1e581cf70
2022-09-04 20:11:52
0
54
0d57d616d4d5061a9972738ead2b65538bef2628eafc9b8bf2c423e33fe056bb
2022-09-04 20:11:52
0
59
96b49fbbdf1bcfe45aa8281beeb1460bb4692103d91e97fe3f9c51b0ea983f23
2022-09-04 20:11:52
0
59
a346b7e1e854ba8249db169af2ea188c079a14e6cf9bf03c2786ad01d0da7e8d
2022-09-04 20:11:49
0
59
383452c35f0dc9530a68c33591c418d04fbd3c27f18e1017e05f445489d02a11
2022-09-04 20:11:46
0
56
a596438cbc7daecbc8c27a1a87a0e7c2c8fd5f600abb87c7a4cd0a39eb76fb51
2022-09-04 20:11:44
0
59
1876e3dfb2a0734b2bb0e646f624f13dd8285493b71053a1ea825f346475fd20
2022-09-04 20:11:41
0
59
3467d969a014df756de001e5653baa78709c62f726f47f82d19a2a55a4a638ef
2022-09-04 20:09:59
0
59
b4442c28e2849f4c674c991ba3b423f1cf154d0761ac35e5352562aa9b84ac90
2022-09-04 02:44:44
0
59
5a6650b1b142ad4a000bfb95f603e064a2385e341b7031f84ee97d1678d3423f
2022-09-04 02:44:43
0
59
5750987c494aa471733cc4608c91923f4cd0838748909843390cb59ba5808509
2022-09-04 02:44:43
0
58
7ef9494058969d345caa9afe7a96598f864a1e445b8b49052e456c3b1f918d41
2022-09-04 02:44:40
0
59
67aa170b819748b4a40e8d98e986bfbbc10a09859646392b4212e6ebeda5d6ae
2022-09-04 02:44:40
0
59
ab64e3e73bed02975472ea45ef85dd9f6422d873c23f42f45e19009968447cbd
2022-09-04 02:44:40
0
59
59920a89d3d99a75ce91bfbdb08a172f77fafbafe320d6294a64f4c26414b31e
2022-09-04 02:44:40
0
59
e735ee27722ac165472e36de0b0adb2b9af818ed85365aee5f016ea2887d454b
2022-09-04 02:44:39
0
58
3b96703e846529363c93072307dcc9c9f2ab793ee25d2f0d644f7149b7fd9b39
2022-09-04 02:44:39
0
59
6c32ea522263d6a5372243a2fee71e383a8e0c1a96015b333ea83cac1f2ce60d
2022-09-04 02:44:39
0
58
81ddae3c55e3b1ab3a802bd8525828a7cf71bdf750129188dd9868308e3b59b1
2022-09-04 02:44:39
0
56
f85ad5f3e98ae381522d9054e82f01b992e4fcf3bf75f87312f6fe946d3817c1
2022-09-04 02:44:39
0
59
b802b45a0e581a4262384b1bd97b6c256ce0a65e009777ffd81fd46d982ae846
2022-09-04 02:44:39
0
59
135de7580c14f6a6955ec33a6fa775309abdc13de2c3c4f706393b02edc52278
2022-09-04 02:44:39
0
59
bd5d907fe21cceecf4dd05e4753d2f78e078d5ed1b88709fab0ac4ebba4ab9ae
2022-09-04 02:44:37
0
59
f78237f4964295d5a4cca5347d203a1aabc0ef2d61b73a351f2489b884ff7e65
2022-09-04 02:44:36
0
59
624465b402619cbd8a1c1e679a8315cd5f4f236d9a029809b9e98a5c49fe3cab
2022-09-04 02:44:36
0
59
c834ac29ff2943d8376fbee86cc594f3e6e5d3fdad02b415193bd3054b6d5786
2022-09-04 02:44:36
0
59
b3d4e43e5c20b74b56e4df3920fd92200f742d7a7aa349c7b21bd00094edd40b
2022-09-04 02:44:36
0
59
90292c24363a6865bfa757b597ab7c7d35d9c0651be8adbc5b0a9b30027830b8
2022-09-04 02:39:19
0
50
685f14270916ecec2af90d1d3129a416938bc0fef314166556a7439efd735af0
2022-09-04 02:39:18
0
59
3527b01da3f5d01fa3e0b4d26def3607f0f6063e150ee5d39733e0203e8150b2
2022-09-04 02:39:17
0
59
4e8d6536af94847ec11595923ad593a7e045a6f59fb74dcf39de0bd3e226a017
2022-09-04 02:39:17
0
59
33ae4dab3c26f381fedb5e2249944fe27ed54f26aba78e33fb46d76bf3636899
2022-09-04 02:39:17
0
56
396d50a6faa31740bbb9f9bf970c27003ab59e11f16dcea6721e43cbc2641acd
2022-09-04 02:39:17
0
59
d50b190d2c031c96a1a5f2cd861490a432ee66efaa336952ebf64dd57812c75d
2022-09-04 02:39:17
0
59
d97569cbd9cf64641a090680a312653043b19dc6f3759e334cf9d8d96533dc3b
2022-09-04 02:39:16
0
59
2651494b4fa18a6f0a025c989ecf6271e630b9a962fd58f6843c0227b628b030
2022-08-21 05:48:25
2
58
82f5e5f8fefc9ad618b154f1b843acbaa37a86d614ccebb50a3d16af77ada994
2022-07-29 06:13:35
1
59
317226a1a5a161b2142644ec82608433e1d9da5e130f6e355c631fccc558a380
2022-07-25 02:25:01
0
59
574dcdf69c7d21fecb2f62ddcc3b1992a1c43584b16327b6752a512b70447889

Rule Matches per Month (last 24 months)