MalwareBazaar Database

This page shows some basic information the YARA rule WiltedTulip_Tools_clrlg_RID306B including corresponding malware samples.

Database Entry


YARA Rule:WiltedTulip_Tools_clrlg_RID306B
Author:Florian Roth
Description:Detects Windows eventlog cleaner used in Operation Wilted Tulip - file clrlg.bat
Firstseen:2026-03-27 04:26:30 UTC
Lastseen:never
Sightings:1

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter