1154 Commits

Author SHA1 Message Date
Jaume Martin b942980fcf Merge pull request #424 from joshlemon/patch-1
Create RANSOM_Revix.yar
2022-04-12 19:53:15 +02:00
Jaume Martin cf3a8653d3 Fixed #421 Deprecated rule MALW_Retefe.yar 2022-04-12 17:50:28 +02:00
KatsuragiCSL 1dabb33f73 pyinstaller on macos 2022-04-01 17:12:35 +08:00
Josh Lemon d5b6728e9d Create RANSOM_Revix.yar 2021-12-07 15:46:02 +11:00
RandomRhythm 12c21f7667 Tighten Glasses rule
Marked GlassesCode rule private to prevent alerting. Modified Glasses rule to require both GlassesCode and GlassesStrings to limit alerting. Added a reference URL and a reference file hash value to the rules. Updated the last modified dates. Tested rules against the reference hash file with both GlassesStrings and Glasses producing detections.

Fixes #422
2021-11-17 21:22:17 -07:00
Steven K 11e24a0080 Create MALW_MacGyver.yar
rule to detect smard-card related hacktool/malwares
2021-05-11 18:14:14 +02:00
Arnim Rupp 1605470db0 add TOOLKIT_Redteam_Tools_by_Name.yar, TOOLKIT_Redteam_Tools_by_GUID.yar, TOOLKIT_Solarwinds_credential_stealer.yar
rules to detect 339 hacktools, mostly c#
2021-01-23 14:57:42 +01:00
Jaume Martin 608de9dfa6 Merge pull request #388 from Xyl2k/patch-4
Create MALW_PurpleWave.yar
2020-12-28 22:04:58 +01:00
Jaume Martin f590ac808f Merge pull request #390 from RandomRhythm/master
change file type comment from exe to jar for JavaDropper : RAT
2020-12-28 22:03:33 +01:00
Jin Kim 2e531cc2e0 trying to pass the CI pipeline 2020-12-23 23:09:32 -06:00
Jin Kim c7c914003c added stuxnet python source code rule 2020-12-23 23:00:52 -06:00
Jin Kim 4f362cca8a added rule for python stuxnet source code. 2020-12-23 22:46:38 -06:00
Ryan B 1384b63810 Marking Surtr referenced rules RSharedStrings, RemoteStrings, and GmRemoteStrings as private to limit false alerts.
RSharedStrings alerts on Microsoft signed wininet.dll	6B39A43271B0A631EAEFDAFDD51D17E3
SharedStrings alerts on Microsoft signed ntoskrnl.exe 68762D4C4412B4BB52BE2FC11F977503

Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
2020-09-21 16:53:21 -06:00
Ryan B 0364f63b2c change file type comment from exe to jar for JavaDropper : RAT
Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
2020-09-11 16:39:34 -06:00
Steven K 1ef319586b Create MALW_PurpleWave.yar
yara rule to detect PurpleWave
2020-08-02 19:42:46 +02:00
Xumeiquer a4a251208d Fixing issues 2020-07-01 22:52:12 +02:00
Jaume Martin a64cb6807a Merge branch 'master' into master 2020-07-01 11:44:25 +02:00
lcol3117 05f0684e7f add .yar extension 2020-06-30 17:18:26 -04:00
lcol3117 43fbf2e4e5 add .yar extension 2020-06-30 17:17:55 -04:00
lcol3117 e514042b8f add .yar extension 2020-06-30 17:17:31 -04:00
lcol3117 e8e9a5c17d add .yar extension 2020-06-30 17:17:00 -04:00
lcol3117 86cf4c1c8a add .yar extension 2020-06-30 17:16:18 -04:00
lcol3117 6fc3a56802 add .yar extension 2020-06-30 17:15:37 -04:00
lcol3117 95d2648ff1 add .yar extension 2020-06-30 17:14:54 -04:00
lcol3117 75f29f140d fix typo, there is a space in the reference
https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-august-31st-2018-devs-on-vacation/
is mentioned as the reference, and the picture has a space between “the” and “decryption”.
2020-06-30 17:14:09 -04:00
lcol3117 33dd74c892 add .yar extension 2020-06-30 17:13:04 -04:00
lcol3117 994d3dec12 add .yar extension 2020-06-30 17:08:20 -04:00
lcol3117 1edbe8e0dd add .yar extension 2020-06-30 17:07:30 -04:00
lcol3117 724127d781 add .yar extension 2020-06-30 17:06:14 -04:00
lcol3117 0dceaf7b31 add .yar extension 2020-06-30 17:05:15 -04:00
lcol3117 7a02b74fb2 add .yar extension 2020-06-30 17:04:19 -04:00
lcol3117 cb219040c4 add .yar extension 2020-06-30 17:03:40 -04:00
lcol3117 91173e61c9 add .yar extension 2020-06-30 17:02:59 -04:00
lcol3117 af96d415c7 add .yar extension 2020-06-30 17:02:13 -04:00
Ryan B e59cdda71c remove spaces before "rule Retefe" in MALW_Retefe.yar
Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
2020-06-28 15:04:37 -06:00
Ryan B a696d67092 add .yar extension to ransom rules and add to index
Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
2020-06-28 10:29:32 -06:00
Ryan B 2e9fc31072 rename malware rules missing .yar extension and add to index.
Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
2020-06-27 22:21:32 -06:00
Jaume Martin 84fcc93829 Merge pull request #377 from baderj/asyncrat
new yara rule for AsyncRAT
2020-06-22 00:01:58 +02:00
Jaume Martin 3ea8928a12 Merge pull request #378 from Nishan8583/master
Snake Ransomware yara rule
2020-06-22 00:01:17 +02:00
spaddex 4c8e2a5ff9 Renamed poetRAT to avoid dupes + adjusted critera
The regex for RAT_PoetRATPython was generating false positives. Adjusted
rule to need hits on at least 3 of the strings
2020-05-23 19:54:23 +02:00
Nishan8583 2d9f8ffe54 Snake Ransomware yara rule 2020-05-15 11:14:55 +05:45
Johannes Bader fa6941b0dd new yara rule for AsyncRAT 2020-05-14 10:48:24 +02:00
Nishan8583 35db229a10 Rules updated to be more focused on the malware as requested 2020-05-07 10:42:22 +05:45
Nishan8583 39a0cc1e88 Poet Rat Rules 2020-05-06 13:56:22 +05:45
Jaume Martin 2bb79cb612 Renamed Njrat to Njrat2 in terms to avoid conflicts 2020-02-24 13:14:20 +01:00
Frank Poz d2bc685a05 Move more generic rules to capabilities category. 2020-01-17 03:13:57 +00:00
Jaume Martin b01380d5d4 Create MalConfScan.yar 2020-01-14 12:34:32 +01:00
Jaume Martin 1026496f44 Merge pull request #348 from DottoPing/patch-5
Update RomeoFoxtrot_mod.yara.error
2020-01-08 12:41:20 +01:00
jovimon ce92a41098 Merge pull request #359 from hwvs/master
Add MALW_FUDCrypt.yar and MALW_MSILStealer.yar
2020-01-07 18:55:43 +01:00
jovimon c453c86164 Update MALW_MSILStealer.yar 2020-01-07 18:55:31 +01:00