21 Commits

Author SHA1 Message Date
Ԝеѕ 580272c051 rename contentis_base64 to contains 2020-07-08 12:44:14 -04:00
Merlin e121fffc50 Add ipv6 support
The IP Rule is lacking IPv6 support.
2020-05-06 12:08:54 +02:00
Malware Utkonos 6d3fa17156 Add detection for hex encoded text PEs
References:
https://blog.reversinglabs.com/blog/rats-in-the-library
https://twitter.com/ItsReallyNick/status/1222985472139579392
2020-02-01 16:36:51 -05:00
Antonio Sánchez eced3058d9 Merge pull request #247 from FliegenEinhorn/master
Thanks!
moving rule maldoc_OLE_file_magic_number to utils/magic.yar
2017-07-11 10:50:57 +00:00
Jaume Martin 306feaef3a Moved Crypto/base64.yar to utils/base64.yar according to #239 and regenerated the index 2017-07-01 18:59:10 +02:00
FliegenEinhorn c20179c37d moving rule maldoc_OLE_file_magic_number to utils/magic.yar 2017-06-16 14:20:56 +02:00
Xumeiquer a853f2608a Added module yara-forensics. 2017-05-02 14:06:44 +02:00
Xumeiquer db39cbb966 removing yara-forensics 2017-05-02 14:05:36 +02:00
Xumeiquer d734671d9d Remove forensic files and create a clone repo of yara-forensics 2017-05-02 13:45:52 +02:00
Xumeiquer 9faf2952f2 Added Forensics rules 2017-04-26 17:33:32 +02:00
mmorenog 8473a65c80 Create README 2017-04-26 10:06:38 +02:00
mmorenog dfcc493001 Update virustotal.yar 2017-04-26 09:46:54 +02:00
mmorenog 1747c46eba Create suspicious_strings.yar 2017-04-26 09:44:39 +02:00
mmorenog a0942e05f4 Create virustotal.yar 2017-04-26 09:35:02 +02:00
mmorenog c90bea86c9 Delete ipv4_pub.yar 2016-12-07 15:07:04 +01:00
mmorenog 6dc6acb6b9 Merge pull request #186 from garanews/master
yara rule to only match public IPv4 address
2016-12-07 14:53:53 +01:00
garanews d8c18eae1b Update ipv4_pub.yar 2016-12-02 08:39:59 +01:00
garanews 32590c9cf0 Rename ipv4_pub to ipv4_pub.yar 2016-12-02 08:28:11 +01:00
garanews c8c198a4fb Create ipv4_pub
yara rule to ONLY match PUBLIC IPv4 address
2016-12-02 08:27:53 +01:00
Antonio S b42bbf6d8f Added domain and URL rules 2016-12-02 08:01:23 +01:00
Antonio S ef6d971f8b Added folder utils and rule to detect IPs 2016-10-06 12:09:33 +02:00