mirror of
https://github.com/Yara-Rules/rules
synced 2026-06-08 12:58:40 +00:00
Create JJencode.yar
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
/*
|
||||
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
|
||||
|
||||
*/
|
||||
rule jjEncode
|
||||
{
|
||||
meta:
|
||||
description = "jjencode detection"
|
||||
ref = "http://blog.xanda.org/2015/06/10/yara-rule-for-jjencode/"
|
||||
author = "adnan.shukor@gmail.com"
|
||||
date = "10-June-2015"
|
||||
version = "1"
|
||||
impact = 3
|
||||
hide = false
|
||||
strings:
|
||||
$jjencode = /(\$|[\S]+)=~\[\]\;(\$|[\S]+)\=\{[\_]{3}\:[\+]{2}(\$|[\S]+)\,[\$]{4}\:\(\!\[\]\+["]{2}\)[\S]+/ fullword
|
||||
condition:
|
||||
$jjencode
|
||||
}
|
||||
Reference in New Issue
Block a user