filename -fix
parent
92684a76c2
commit
d121a356fe
|
@ -1,4 +1,4 @@
|
|||
id: malware-aar
|
||||
id: aar-malware
|
||||
|
||||
info:
|
||||
name: AAR Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-adzok
|
||||
id: adzok-malware
|
||||
|
||||
info:
|
||||
name: Adzok Malware - Detect
|
||||
|
@ -14,7 +14,7 @@ file:
|
|||
matchers-condition: or
|
||||
matchers:
|
||||
- type: word
|
||||
part: raw
|
||||
part: raw
|
||||
words:
|
||||
- "key.classPK"
|
||||
- "svd$1.classPK"
|
||||
|
@ -26,7 +26,7 @@ file:
|
|||
condition: and
|
||||
|
||||
- type: word
|
||||
part: raw
|
||||
part: raw
|
||||
words:
|
||||
- "config.xmlPK"
|
||||
- "svd$1.classPK"
|
||||
|
@ -38,6 +38,7 @@ file:
|
|||
condition: and
|
||||
|
||||
- type: word
|
||||
part: raw
|
||||
words:
|
||||
- "config.xmlPK"
|
||||
- "key.classPK"
|
||||
|
@ -49,6 +50,7 @@ file:
|
|||
condition: and
|
||||
|
||||
- type: word
|
||||
part: raw
|
||||
words:
|
||||
- "config.xmlPK"
|
||||
- "key.classPK"
|
||||
|
@ -60,7 +62,7 @@ file:
|
|||
condition: and
|
||||
|
||||
- type: word
|
||||
part: raw
|
||||
part: raw
|
||||
words:
|
||||
- "config.xmlPK"
|
||||
- "key.classPK"
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-alfa
|
||||
id: alfa-malware
|
||||
|
||||
info:
|
||||
name: Alfa Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-alienspy
|
||||
id: alienspy-malware
|
||||
|
||||
info:
|
||||
name: AlienSpy Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-alina
|
||||
id: alina-malware
|
||||
|
||||
info:
|
||||
name: Alina Malware - Detect
|
||||
|
@ -13,7 +13,7 @@ file:
|
|||
|
||||
matchers:
|
||||
- type: word
|
||||
part: raw
|
||||
part: raw
|
||||
words:
|
||||
- 'Alina v1.0'
|
||||
- 'POST'
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-alpha
|
||||
id: alpha-malware
|
||||
|
||||
info:
|
||||
name: Alpha Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-andromeda
|
||||
id: andromeda-malware
|
||||
|
||||
info:
|
||||
name: Andromeda Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-ap0calypse
|
||||
id: ap0calypse-malware
|
||||
|
||||
info:
|
||||
name: Ap0calypse Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-arcom
|
||||
id: arcom-malware
|
||||
|
||||
info:
|
||||
name: Arcom Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-arkei
|
||||
id: arkei-malware
|
||||
|
||||
info:
|
||||
name: Arkei Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-backoff
|
||||
id: backoff-malware
|
||||
|
||||
info:
|
||||
name: Backoff Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-bandook
|
||||
id: bandook-malware
|
||||
|
||||
info:
|
||||
name: Bandook Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-blacknix
|
||||
id: blacknix-malware
|
||||
|
||||
info:
|
||||
name: BlackNix Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-blackworm
|
||||
id: blackworm-malware
|
||||
|
||||
info:
|
||||
name: Blackworm Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-bluebanana
|
||||
id: bluebanana-malware
|
||||
|
||||
info:
|
||||
name: BlueBanana Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-bozok
|
||||
id: bozok-malware
|
||||
|
||||
info:
|
||||
name: Bozok Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-bublik
|
||||
id: bublik-malware
|
||||
|
||||
info:
|
||||
name: Bublik Malware Detector
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-cap-hookexkeylogger
|
||||
id: cap-hookexkeylogger-malware
|
||||
|
||||
info:
|
||||
name: CAP HookExKeylogger Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-cerberus
|
||||
id: cerberus-malware
|
||||
|
||||
info:
|
||||
name: Cerberus Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-clientmesh
|
||||
id: clientmesh-malware
|
||||
|
||||
info:
|
||||
name: ClientMesh Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-crimson
|
||||
id: crimson-malware
|
||||
|
||||
info:
|
||||
name: Crimson Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-cryptxxx-dropper
|
||||
id: cryptxxx-dropper-malware
|
||||
|
||||
info:
|
||||
name: CryptXXX Dropper Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-cryptxxx
|
||||
id: cryptxxx-malware
|
||||
|
||||
info:
|
||||
name: CryptXXX Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-cxpid
|
||||
id: cxpid-malware
|
||||
|
||||
info:
|
||||
name: Cxpid Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-cythosia
|
||||
id: cythosia-malware
|
||||
|
||||
info:
|
||||
name: Cythosia Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-darkrat
|
||||
id: darkrat-malware
|
||||
|
||||
info:
|
||||
name: DarkRAT Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-ddostf
|
||||
id: ddostf-malware
|
||||
|
||||
info:
|
||||
name: DDoSTf Malware - Detect
|
||||
|
@ -25,6 +25,6 @@ file:
|
|||
|
||||
- type: binary
|
||||
binary:
|
||||
- 'E8AEBEE7BDAE5443505F4B454550494E54564CE99499E8AFAFEFBC9A00' #TCP_KEEPINTVL
|
||||
- 'E8AEBEE7BDAE5443505F4B454550434E54E99499E8AFAFEFBC9A00' #TCP_KEEPCNT
|
||||
- 'E8AEBEE7BDAE5443505F4B454550494E54564CE99499E8AFAFEFBC9A00'
|
||||
- 'E8AEBEE7BDAE5443505F4B454550434E54E99499E8AFAFEFBC9A00'
|
||||
condition: and
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-derkziel
|
||||
id: derkziel-malware
|
||||
|
||||
info:
|
||||
name: Derkziel Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-dexter
|
||||
id: dexter-malware
|
||||
|
||||
info:
|
||||
name: Dexter Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-diamondfox
|
||||
id: diamondfox-malware
|
||||
|
||||
info:
|
||||
name: DiamondFox Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-dmalocker
|
||||
id: dmalocker-malware
|
||||
|
||||
info:
|
||||
name: DMA Locker Malware - Detect
|
||||
|
@ -19,4 +19,4 @@ file:
|
|||
- "21444d414c4f434b332e30"
|
||||
- "3F520000FFFFFFFF06000000524C4141"
|
||||
- "21444d414c4f434b342e30"
|
||||
condition: or
|
||||
condition: or
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-doublepulsar
|
||||
id: doublepulsar-malware
|
||||
|
||||
info:
|
||||
name: DoublePulsar Malware - Detect
|
||||
|
@ -14,6 +14,6 @@ file:
|
|||
matchers:
|
||||
- type: binary
|
||||
binary:
|
||||
- "FD0C8C5CB8C424C5CCCCCC0EE8CC246BCCCCCC0F24CDCCCCCC275C9775BACDCCCCC3FE" #xor
|
||||
- "45208D938D928D918D90929391970F9F9E9D99844529844D20CCCDCCCC9B844503844514844549CC3333332477CCCCCC844549C43333332484CDCCCC844549DC333333844749CC333333844741" #dll
|
||||
condition: or
|
||||
- "FD0C8C5CB8C424C5CCCCCC0EE8CC246BCCCCCC0F24CDCCCCCC275C9775BACDCCCCC3FE"
|
||||
- "45208D938D928D918D90929391970F9F9E9D99844529844D20CCCDCCCC9B844503844514844549CC3333332477CCCCCC844549C43333332484CDCCCC844549DC333333844749CC333333844741"
|
||||
condition: or
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-eicar
|
||||
id: eicar-malware
|
||||
|
||||
info:
|
||||
name: Eicar Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-erebus
|
||||
id: erebus-malware
|
||||
|
||||
info:
|
||||
name: Erebus Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-ezcob
|
||||
id: ezcob-malware
|
||||
|
||||
info:
|
||||
name: Ezcob Malware - Detect
|
||||
|
@ -20,4 +20,4 @@ file:
|
|||
- 'Ezcob'
|
||||
- 'l\x12i\x12u\x122\x120\x121\x123\x120\x124\x121\x126'
|
||||
- '20110113144935'
|
||||
condition: or
|
||||
condition: or
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-fudcrypt
|
||||
id: fudcrypt-malware
|
||||
|
||||
info:
|
||||
name: FUDCrypt Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-gafgyt-bash
|
||||
id: gafgyt-bash-malware
|
||||
|
||||
info:
|
||||
name: Gafgyt Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-gafgyt-generic
|
||||
id: gafgyt-generic-malware
|
||||
|
||||
info:
|
||||
name: Gafgyt Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-gafgyt-hihi
|
||||
id: gafgyt-hihi-malware
|
||||
|
||||
info:
|
||||
name: Gafgyt Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-gafgyt-hoho
|
||||
id: gafgyt-hoho-malware
|
||||
|
||||
info:
|
||||
name: Gafgyt Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-gafgyt-jackmy
|
||||
id: gafgyt-jackmy-malware
|
||||
|
||||
info:
|
||||
name: Gafgyt Malware - Detect
|
|
@ -1,7 +1,7 @@
|
|||
id: malware-gafgyt-oh
|
||||
id: gafgyt-oh-malware
|
||||
|
||||
info:
|
||||
name: Gafgyt Malware - Detect
|
||||
name: Gafgyt Oh Malware - Detect
|
||||
author: daffainfo
|
||||
severity: info
|
||||
reference: https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Gafgyt.yar
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-genome
|
||||
id: genome-malware
|
||||
|
||||
info:
|
||||
name: Genome Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-glass
|
||||
id: glass-malware
|
||||
|
||||
info:
|
||||
name: Glass Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-glasses
|
||||
id: glasses-malware
|
||||
|
||||
info:
|
||||
name: Glasses Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-gozi
|
||||
id: gozi-malware
|
||||
|
||||
info:
|
||||
name: Gozi Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-gpgqwerty
|
||||
id: gpgqwerty-malware
|
||||
|
||||
info:
|
||||
name: GPGQwerty Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-greame
|
||||
id: greame-malware
|
||||
|
||||
info:
|
||||
name: Greame Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-grozlex
|
||||
id: grozlex-malware
|
||||
|
||||
info:
|
||||
name: Grozlex Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-hawkeye
|
||||
id: hawkeye-malware
|
||||
|
||||
info:
|
||||
name: HawkEye Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-imminent
|
||||
id: imminent-malware
|
||||
|
||||
info:
|
||||
name: Imminent Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-infinity
|
||||
id: infinity-malware
|
||||
|
||||
info:
|
||||
name: Infinity Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-insta11
|
||||
id: insta11-malware
|
||||
|
||||
info:
|
||||
name: Insta11 Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-intel-virtualization
|
||||
id: intel-virtualization-malware
|
||||
|
||||
info:
|
||||
name: Intel Virtualization Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-iotreaper
|
||||
id: iotreaper-malware
|
||||
|
||||
info:
|
||||
name: IotReaper Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-linux-aesddos
|
||||
id: linux-aesddos-malware
|
||||
|
||||
info:
|
||||
name: Linux AESDDOS Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-linux-billgates
|
||||
id: linux-billgates-malware
|
||||
|
||||
info:
|
||||
name: Linux BillGates Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-linux-elknot
|
||||
id: linux-elknot-malware
|
||||
|
||||
info:
|
||||
name: Linux Elknot Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-linux-mrblack
|
||||
id: linux-mrblack-malware
|
||||
|
||||
info:
|
||||
name: Linux MrBlack Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-linux-tsunami
|
||||
id: linux-tsunami-malware
|
||||
|
||||
info:
|
||||
name: Linux Tsunami Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-locky
|
||||
id: locky-malware
|
||||
|
||||
info:
|
||||
name: Locky Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-lostdoor
|
||||
id: lostdoor-malware
|
||||
|
||||
info:
|
||||
name: LostDoor Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-luminositylink
|
||||
id: luminositylink-malware
|
||||
|
||||
info:
|
||||
name: LuminosityLink Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-luxnet
|
||||
id: luxnet-malware
|
||||
|
||||
info:
|
||||
name: LuxNet Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-macgyver-installer
|
||||
id: macgyver-installer--malware
|
||||
|
||||
info:
|
||||
name: MacGyver.cap Installer Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-macgyver
|
||||
id: macgyver-malware
|
||||
|
||||
info:
|
||||
name: MacGyver.cap Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-madness
|
||||
id: madness-malware
|
||||
|
||||
info:
|
||||
name: Madness DDOS Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-miner
|
||||
id: miner-malware
|
||||
|
||||
info:
|
||||
name: Miner Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-miniasp3
|
||||
id: miniasp3-malware
|
||||
|
||||
info:
|
||||
name: MiniASP3 Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-naikon
|
||||
id: naikon-malware
|
||||
|
||||
info:
|
||||
name: Naikon Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-naspyupdate
|
||||
id: naspyupdate-malware
|
||||
|
||||
info:
|
||||
name: nAspyUpdate Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-notepad
|
||||
id: notepad-malware
|
||||
|
||||
info:
|
||||
name: Notepad v1.1 Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-olyx
|
||||
id: olyx-malware
|
||||
|
||||
info:
|
||||
name: Olyx Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-osx-leverage
|
||||
id: osx-leverage-malware
|
||||
|
||||
info:
|
||||
name: OSX Leverage Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-paradox
|
||||
id: paradox-malware
|
||||
|
||||
info:
|
||||
name: Paradox Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-plasma
|
||||
id: plasma-malware
|
||||
|
||||
info:
|
||||
name: Plasma Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-poetrat
|
||||
id: poetrat-malware
|
||||
|
||||
info:
|
||||
name: PoetRat Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-pony
|
||||
id: pony-malware
|
||||
|
||||
info:
|
||||
name: Pony Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-pubsab
|
||||
id: pubsab-malware
|
||||
|
||||
info:
|
||||
name: PubSab Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-punisher
|
||||
id: punisher-malware
|
||||
|
||||
info:
|
||||
name: Punisher Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-pypi
|
||||
id: pypi-malware
|
||||
|
||||
info:
|
||||
name: Fake PyPI Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-pythorat
|
||||
id: pythorat-malware
|
||||
|
||||
info:
|
||||
name: PythoRAT Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-qrat
|
||||
id: qrat-malware
|
||||
|
||||
info:
|
||||
name: QRat Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-satana-dropper
|
||||
id: satana-dropper-malware
|
||||
|
||||
info:
|
||||
name: Satana Dropper Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-satana
|
||||
id: satana-malware
|
||||
|
||||
info:
|
||||
name: Satana Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-shimrat
|
||||
id: shimrat-malware
|
||||
|
||||
info:
|
||||
name: ShimRat Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-shimratreporter
|
||||
id: shimratreporter-malware
|
||||
|
||||
info:
|
||||
name: ShimRatReporter Malware - Detect
|
||||
|
@ -13,7 +13,7 @@ file:
|
|||
|
||||
matchers:
|
||||
- type: word
|
||||
part: raw
|
||||
part: raw
|
||||
words:
|
||||
- "IP-INFO"
|
||||
- "Network-INFO"
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-sigma
|
||||
id: sigma-malware
|
||||
|
||||
info:
|
||||
name: Sigma Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-smallnet
|
||||
id: smallnet-malware
|
||||
|
||||
info:
|
||||
name: SmallNet Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-snake
|
||||
id: snake-malware
|
||||
|
||||
info:
|
||||
name: Snake Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-sub7nation
|
||||
id: sub7nation-malware
|
||||
|
||||
info:
|
||||
name: Sub7Nation Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-t5000
|
||||
id: t5000-malware
|
||||
|
||||
info:
|
||||
name: T5000 Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-tedroo
|
||||
id: tedroo-malware
|
||||
|
||||
info:
|
||||
name: Tedroo Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-terminator
|
||||
id: terminator-malware
|
||||
|
||||
info:
|
||||
name: Terminator Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-teslacrypt
|
||||
id: teslacrypt-malware
|
||||
|
||||
info:
|
||||
name: TeslaCrypt Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-tox
|
||||
id: tox-malware
|
||||
|
||||
info:
|
||||
name: Tox Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-treasurehunt
|
||||
id: treasurehunt-malware
|
||||
|
||||
info:
|
||||
name: Trickbot Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-trickbot
|
||||
id: trickbot-malware
|
||||
|
||||
info:
|
||||
name: Trickbot Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-trumpbot
|
||||
id: trumpbot-malware
|
||||
|
||||
info:
|
||||
name: TrumpBot Malware - Detect
|
|
@ -1,4 +1,4 @@
|
|||
id: malware-universal-1337
|
||||
id: universal-1337-malware
|
||||
|
||||
info:
|
||||
name: Universal 1337 Stealer Malware - Detect
|
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue