WEBSHELL_PHP_Tiny_Jun21_1

Rule Info

Description
Detects tiny PHP web shells
Reference
Internal Research
Tags
['WEBSHELL', 'T1100']
Date
2021-06-05
Required Modules
[]
Rule Hash
ccbf54e6edf6b48b97192e776397b96c
Score
75
Av Ratio
6.77
Name
WEBSHELL_PHP_Tiny_Jun21_1
Author
Florian Roth
Minimum Yara
1.7

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
3
Suspicious (< 10 engines)
26
Clean (0 engines)
1

Rule Matches

Total
Timestamp
Hash
Positives
VT
57
2022-05-19 10:20:42
756934f30ca23757fc348cbb0080c8846ae6004a509a2be8125851f7f042a9cd
23
58
2022-05-03 17:26:24
001724c14d9405376aec15e8fea5e486903948b7f8fe12d22d42cf6a9376d937
1
58
2022-05-02 15:49:19
61c6b718e774ddadc78660e3176c6799ed7cf8e45e919d0b17ab16644256af37
1
58
2022-05-02 15:42:33
2416238fc41f27098138edecff4085d85606c5ae906505b7ec5f49e1c25922aa
1
58
2022-05-02 15:42:30
1259a5679d2005a94f4589bb9eed6ff1716e8b344d52b64f11f8e8004754496a
1
58
2022-05-02 15:38:59
1032c577add2394d5aee8743983aa64c0cb355311fc415803385bc412021457c
1
58
2022-05-02 15:37:49
ac8415473e3f6d8723ae4f1ebc326d957739b300fe2aef92f7f4004bfa3b9390
1
57
2022-05-02 15:35:30
d0f51313701248f567506f062561d66ca0581544afc093683c4f69172b21d2b6
1
58
2022-05-02 15:35:27
8e5b583f13cccf6babd69b39d942df2d8972a1188e1e12167d9c85adce0cc016
0
57
2022-05-02 13:16:44
2f25dad491b9a238a151a97c565610c11046e6ad97cf668a3c1b636fe273e07f
1
57
2022-04-30 12:00:36
dca7866fe77706ae880d8f6bbdf3a71b969d2fdde887343a77bea73c97a1ad8a
2
58
2022-04-30 11:50:58
8faeaf92aedd3db39d5969f67f2623db848bc77e308a3cd51307836dcef72bb7
1
58
2022-04-30 11:42:00
7e0b4342e00198628658e687ae10457eeb45fb1c8d8d75c8c7fc8062a278f810
2
58
2022-04-30 11:36:24
ce4b4e8a685337dbb455788ccc6071304324c2bd20125c3b3b3e1b1d192b0544
2
58
2022-04-25 11:20:41
44f5f7d6ad4d523505af26b232efb6534d8867c405f0b2243210a9f810f679b0
4
57
2022-04-20 11:03:41
140323cf30bc12b467e141ddc83f1cc7b79d3e1dd72669f9814786b23373cc59
5
55
2022-03-18 02:50:34
99ac30084924ad81051626695f86ecfea13240f935c9cd814a3b2564ce213973
4
55
2022-01-23 09:19:18
90b75274aee9ff0bcfe95689047ce2d6f80d17dd188c8a1004ccdd4c72d80edc
10
57
2022-01-17 03:14:39
466b264d1ced24a18fd45cbbe346e1f01997c5fdd020f56d8f3b941b592b5c7c
6
50
2021-12-24 17:10:54
9d046ceed720471c4491fe86a88c75e9c155333d77d84540a8e03a851cf08ac2
5
56
2021-11-30 08:52:41
d411bbf7116a6047ee3d7b7e191ef4b30857d2cffd454158c84b1fa8c9b5e96a
3
54
2021-11-29 06:08:31
f15cc41c3ed95a868eabe758dacbe49fed71f33fc135ff1ed1ca136abb52c0e1
1
57
2021-10-21 05:47:41
4e289b2fafd29e62154a6901b92a56802cc4286edfe2d32877f764c92039369b
7
57
2021-10-20 16:09:09
2309aee5d6244b80e7b1f98d62c87d68e97e0acaf233688af07b6a8439f85b7d
2
57
2021-09-23 10:32:48
474ef152a175617cf0e4e84bc197614ee5cc15169dfe9c61d6acec5053c94331
3
55
2021-09-05 08:54:58
88153cf2b3dbc25f33f09271f7e4acbf5a6002919173ab1c789b1d2576673bd3
5
57
2021-08-31 15:24:15
5b1207402cd8e3a9ca11a817b80496a7989fcee21df1128223b07d9547d68090
3
58
2021-07-24 03:16:20
ff9415170eaba09b3409fdbedfc6b99e29716c6c3764d8de4cce51834bad2ce9
2
59
2021-07-06 07:28:25
45443b30848cc41f111ae3effbe4493b8aafaf39e73c42d268a2461da9831763
10
58
2021-07-02 12:34:42
0c07914dd2148ff3bcba3a53695d70cbaba5ec6820b7f36e5ab77b190ea517f3
7

Rule Matches per Month (last 24 months)