mirror of
https://github.com/Yara-Rules/rules
synced 2026-06-08 12:58:40 +00:00
Create APT_Win_Pipcreat.yar
This commit is contained in:
@@ -0,0 +1,25 @@
|
||||
/*
|
||||
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
|
||||
|
||||
*/
|
||||
|
||||
rule APT_Win_Pipcreat {
|
||||
meta:
|
||||
author = "chort (@chort0)"
|
||||
description = "APT backdoor Pipcreat"
|
||||
filetype = "pe,dll"
|
||||
date = "2013-03"
|
||||
MD5 = "f09d832bea93cf320986b53fce4b8397" // (incorrectly?) identified as Hupigon by many AV on VT
|
||||
Reference = "http://www.cyberengineeringservices.com/login-exe-analysis-trojan-pipcreat/"
|
||||
version = "1.0"
|
||||
strings:
|
||||
$strA = "pip creat failed" wide fullword
|
||||
$strB = "CraatePipe" ascii fullword
|
||||
$strC = "are you there? " wide fullword
|
||||
$strD = "success kill process ok" wide fullword
|
||||
$strE = "Vista|08|Win7" wide fullword
|
||||
$rut = "are you there!@#$%^&*()_+" ascii fullword
|
||||
|
||||
condition:
|
||||
$rut or (2 of ($str*))
|
||||
}
|
||||
Reference in New Issue
Block a user