filename -fix

patch-1
pussycat0x 2023-08-01 17:07:58 +05:30
parent 92684a76c2
commit d121a356fe
111 changed files with 126 additions and 124 deletions

View File

@ -1,4 +1,4 @@
id: malware-aar id: aar-malware
info: info:
name: AAR Malware - Detect name: AAR Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-adzok id: adzok-malware
info: info:
name: Adzok Malware - Detect name: Adzok Malware - Detect
@ -38,6 +38,7 @@ file:
condition: and condition: and
- type: word - type: word
part: raw
words: words:
- "config.xmlPK" - "config.xmlPK"
- "key.classPK" - "key.classPK"
@ -49,6 +50,7 @@ file:
condition: and condition: and
- type: word - type: word
part: raw
words: words:
- "config.xmlPK" - "config.xmlPK"
- "key.classPK" - "key.classPK"

View File

@ -1,4 +1,4 @@
id: malware-alfa id: alfa-malware
info: info:
name: Alfa Malware - Detect name: Alfa Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-alienspy id: alienspy-malware
info: info:
name: AlienSpy Malware - Detect name: AlienSpy Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-alina id: alina-malware
info: info:
name: Alina Malware - Detect name: Alina Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-alpha id: alpha-malware
info: info:
name: Alpha Malware - Detect name: Alpha Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-andromeda id: andromeda-malware
info: info:
name: Andromeda Malware - Detect name: Andromeda Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-ap0calypse id: ap0calypse-malware
info: info:
name: Ap0calypse Malware - Detect name: Ap0calypse Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-arcom id: arcom-malware
info: info:
name: Arcom Malware - Detect name: Arcom Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-arkei id: arkei-malware
info: info:
name: Arkei Malware - Detect name: Arkei Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-backoff id: backoff-malware
info: info:
name: Backoff Malware - Detect name: Backoff Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-bandook id: bandook-malware
info: info:
name: Bandook Malware - Detect name: Bandook Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-blacknix id: blacknix-malware
info: info:
name: BlackNix Malware - Detect name: BlackNix Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-blackworm id: blackworm-malware
info: info:
name: Blackworm Malware - Detect name: Blackworm Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-bluebanana id: bluebanana-malware
info: info:
name: BlueBanana Malware - Detect name: BlueBanana Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-bozok id: bozok-malware
info: info:
name: Bozok Malware - Detect name: Bozok Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-bublik id: bublik-malware
info: info:
name: Bublik Malware Detector name: Bublik Malware Detector

View File

@ -1,4 +1,4 @@
id: malware-cap-hookexkeylogger id: cap-hookexkeylogger-malware
info: info:
name: CAP HookExKeylogger Malware - Detect name: CAP HookExKeylogger Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-cerberus id: cerberus-malware
info: info:
name: Cerberus Malware - Detect name: Cerberus Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-clientmesh id: clientmesh-malware
info: info:
name: ClientMesh Malware - Detect name: ClientMesh Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-crimson id: crimson-malware
info: info:
name: Crimson Malware - Detect name: Crimson Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-cryptxxx-dropper id: cryptxxx-dropper-malware
info: info:
name: CryptXXX Dropper Malware - Detect name: CryptXXX Dropper Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-cryptxxx id: cryptxxx-malware
info: info:
name: CryptXXX Malware - Detect name: CryptXXX Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-cxpid id: cxpid-malware
info: info:
name: Cxpid Malware - Detect name: Cxpid Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-cythosia id: cythosia-malware
info: info:
name: Cythosia Malware - Detect name: Cythosia Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-darkrat id: darkrat-malware
info: info:
name: DarkRAT Malware - Detect name: DarkRAT Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-ddostf id: ddostf-malware
info: info:
name: DDoSTf Malware - Detect name: DDoSTf Malware - Detect
@ -25,6 +25,6 @@ file:
- type: binary - type: binary
binary: binary:
- 'E8AEBEE7BDAE5443505F4B454550494E54564CE99499E8AFAFEFBC9A00' #TCP_KEEPINTVL - 'E8AEBEE7BDAE5443505F4B454550494E54564CE99499E8AFAFEFBC9A00'
- 'E8AEBEE7BDAE5443505F4B454550434E54E99499E8AFAFEFBC9A00' #TCP_KEEPCNT - 'E8AEBEE7BDAE5443505F4B454550434E54E99499E8AFAFEFBC9A00'
condition: and condition: and

View File

@ -1,4 +1,4 @@
id: malware-derkziel id: derkziel-malware
info: info:
name: Derkziel Malware - Detect name: Derkziel Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-dexter id: dexter-malware
info: info:
name: Dexter Malware - Detect name: Dexter Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-diamondfox id: diamondfox-malware
info: info:
name: DiamondFox Malware - Detect name: DiamondFox Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-dmalocker id: dmalocker-malware
info: info:
name: DMA Locker Malware - Detect name: DMA Locker Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-doublepulsar id: doublepulsar-malware
info: info:
name: DoublePulsar Malware - Detect name: DoublePulsar Malware - Detect
@ -14,6 +14,6 @@ file:
matchers: matchers:
- type: binary - type: binary
binary: binary:
- "FD0C8C5CB8C424C5CCCCCC0EE8CC246BCCCCCC0F24CDCCCCCC275C9775BACDCCCCC3FE" #xor - "FD0C8C5CB8C424C5CCCCCC0EE8CC246BCCCCCC0F24CDCCCCCC275C9775BACDCCCCC3FE"
- "45208D938D928D918D90929391970F9F9E9D99844529844D20CCCDCCCC9B844503844514844549CC3333332477CCCCCC844549C43333332484CDCCCC844549DC333333844749CC333333844741" #dll - "45208D938D928D918D90929391970F9F9E9D99844529844D20CCCDCCCC9B844503844514844549CC3333332477CCCCCC844549C43333332484CDCCCC844549DC333333844749CC333333844741"
condition: or condition: or

View File

@ -1,4 +1,4 @@
id: malware-eicar id: eicar-malware
info: info:
name: Eicar Malware - Detect name: Eicar Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-erebus id: erebus-malware
info: info:
name: Erebus Malware - Detect name: Erebus Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-ezcob id: ezcob-malware
info: info:
name: Ezcob Malware - Detect name: Ezcob Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-fudcrypt id: fudcrypt-malware
info: info:
name: FUDCrypt Malware - Detect name: FUDCrypt Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-gafgyt-bash id: gafgyt-bash-malware
info: info:
name: Gafgyt Malware - Detect name: Gafgyt Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-gafgyt-generic id: gafgyt-generic-malware
info: info:
name: Gafgyt Malware - Detect name: Gafgyt Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-gafgyt-hihi id: gafgyt-hihi-malware
info: info:
name: Gafgyt Malware - Detect name: Gafgyt Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-gafgyt-hoho id: gafgyt-hoho-malware
info: info:
name: Gafgyt Malware - Detect name: Gafgyt Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-gafgyt-jackmy id: gafgyt-jackmy-malware
info: info:
name: Gafgyt Malware - Detect name: Gafgyt Malware - Detect

View File

@ -1,7 +1,7 @@
id: malware-gafgyt-oh id: gafgyt-oh-malware
info: info:
name: Gafgyt Malware - Detect name: Gafgyt Oh Malware - Detect
author: daffainfo author: daffainfo
severity: info severity: info
reference: https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Gafgyt.yar reference: https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Gafgyt.yar

View File

@ -1,4 +1,4 @@
id: malware-genome id: genome-malware
info: info:
name: Genome Malware - Detect name: Genome Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-glass id: glass-malware
info: info:
name: Glass Malware - Detect name: Glass Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-glasses id: glasses-malware
info: info:
name: Glasses Malware - Detect name: Glasses Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-gozi id: gozi-malware
info: info:
name: Gozi Malware - Detect name: Gozi Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-gpgqwerty id: gpgqwerty-malware
info: info:
name: GPGQwerty Malware - Detect name: GPGQwerty Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-greame id: greame-malware
info: info:
name: Greame Malware - Detect name: Greame Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-grozlex id: grozlex-malware
info: info:
name: Grozlex Malware - Detect name: Grozlex Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-hawkeye id: hawkeye-malware
info: info:
name: HawkEye Malware - Detect name: HawkEye Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-imminent id: imminent-malware
info: info:
name: Imminent Malware - Detect name: Imminent Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-infinity id: infinity-malware
info: info:
name: Infinity Malware - Detect name: Infinity Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-insta11 id: insta11-malware
info: info:
name: Insta11 Malware - Detect name: Insta11 Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-intel-virtualization id: intel-virtualization-malware
info: info:
name: Intel Virtualization Malware - Detect name: Intel Virtualization Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-iotreaper id: iotreaper-malware
info: info:
name: IotReaper Malware - Detect name: IotReaper Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-linux-aesddos id: linux-aesddos-malware
info: info:
name: Linux AESDDOS Malware - Detect name: Linux AESDDOS Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-linux-billgates id: linux-billgates-malware
info: info:
name: Linux BillGates Malware - Detect name: Linux BillGates Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-linux-elknot id: linux-elknot-malware
info: info:
name: Linux Elknot Malware - Detect name: Linux Elknot Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-linux-mrblack id: linux-mrblack-malware
info: info:
name: Linux MrBlack Malware - Detect name: Linux MrBlack Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-linux-tsunami id: linux-tsunami-malware
info: info:
name: Linux Tsunami Malware - Detect name: Linux Tsunami Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-locky id: locky-malware
info: info:
name: Locky Malware - Detect name: Locky Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-lostdoor id: lostdoor-malware
info: info:
name: LostDoor Malware - Detect name: LostDoor Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-luminositylink id: luminositylink-malware
info: info:
name: LuminosityLink Malware - Detect name: LuminosityLink Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-luxnet id: luxnet-malware
info: info:
name: LuxNet Malware - Detect name: LuxNet Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-macgyver-installer id: macgyver-installer--malware
info: info:
name: MacGyver.cap Installer Malware - Detect name: MacGyver.cap Installer Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-macgyver id: macgyver-malware
info: info:
name: MacGyver.cap Malware - Detect name: MacGyver.cap Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-madness id: madness-malware
info: info:
name: Madness DDOS Malware - Detect name: Madness DDOS Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-miner id: miner-malware
info: info:
name: Miner Malware - Detect name: Miner Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-miniasp3 id: miniasp3-malware
info: info:
name: MiniASP3 Malware - Detect name: MiniASP3 Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-naikon id: naikon-malware
info: info:
name: Naikon Malware - Detect name: Naikon Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-naspyupdate id: naspyupdate-malware
info: info:
name: nAspyUpdate Malware - Detect name: nAspyUpdate Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-notepad id: notepad-malware
info: info:
name: Notepad v1.1 Malware - Detect name: Notepad v1.1 Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-olyx id: olyx-malware
info: info:
name: Olyx Malware - Detect name: Olyx Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-osx-leverage id: osx-leverage-malware
info: info:
name: OSX Leverage Malware - Detect name: OSX Leverage Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-paradox id: paradox-malware
info: info:
name: Paradox Malware - Detect name: Paradox Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-plasma id: plasma-malware
info: info:
name: Plasma Malware - Detect name: Plasma Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-poetrat id: poetrat-malware
info: info:
name: PoetRat Malware - Detect name: PoetRat Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-pony id: pony-malware
info: info:
name: Pony Malware - Detect name: Pony Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-pubsab id: pubsab-malware
info: info:
name: PubSab Malware - Detect name: PubSab Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-punisher id: punisher-malware
info: info:
name: Punisher Malware - Detect name: Punisher Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-pypi id: pypi-malware
info: info:
name: Fake PyPI Malware - Detect name: Fake PyPI Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-pythorat id: pythorat-malware
info: info:
name: PythoRAT Malware - Detect name: PythoRAT Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-qrat id: qrat-malware
info: info:
name: QRat Malware - Detect name: QRat Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-satana-dropper id: satana-dropper-malware
info: info:
name: Satana Dropper Malware - Detect name: Satana Dropper Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-satana id: satana-malware
info: info:
name: Satana Malware - Detect name: Satana Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-shimrat id: shimrat-malware
info: info:
name: ShimRat Malware - Detect name: ShimRat Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-shimratreporter id: shimratreporter-malware
info: info:
name: ShimRatReporter Malware - Detect name: ShimRatReporter Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-sigma id: sigma-malware
info: info:
name: Sigma Malware - Detect name: Sigma Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-smallnet id: smallnet-malware
info: info:
name: SmallNet Malware - Detect name: SmallNet Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-snake id: snake-malware
info: info:
name: Snake Malware - Detect name: Snake Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-sub7nation id: sub7nation-malware
info: info:
name: Sub7Nation Malware - Detect name: Sub7Nation Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-t5000 id: t5000-malware
info: info:
name: T5000 Malware - Detect name: T5000 Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-tedroo id: tedroo-malware
info: info:
name: Tedroo Malware - Detect name: Tedroo Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-terminator id: terminator-malware
info: info:
name: Terminator Malware - Detect name: Terminator Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-teslacrypt id: teslacrypt-malware
info: info:
name: TeslaCrypt Malware - Detect name: TeslaCrypt Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-tox id: tox-malware
info: info:
name: Tox Malware - Detect name: Tox Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-treasurehunt id: treasurehunt-malware
info: info:
name: Trickbot Malware - Detect name: Trickbot Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-trickbot id: trickbot-malware
info: info:
name: Trickbot Malware - Detect name: Trickbot Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-trumpbot id: trumpbot-malware
info: info:
name: TrumpBot Malware - Detect name: TrumpBot Malware - Detect

View File

@ -1,4 +1,4 @@
id: malware-universal-1337 id: universal-1337-malware
info: info:
name: Universal 1337 Stealer Malware - Detect name: Universal 1337 Stealer Malware - Detect

Some files were not shown because too many files have changed in this diff Show More